๐Ÿ” CVE Alert

CVE-2026-84829

UNKNOWN 0.0

Optimole < 4.2.12 - Unauthenticated Stored XSS via Srcset Descriptor Parameter

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Optimole WordPress plugin before 4.2.12 does not properly escape a user supplied value before using it to build an image tag attribute, allowing unauthenticated users to inject arbitrary attributes into pages served to every visitor, which leads to Stored Cross-Site Scripting.

Vendor unknown
Product optimole
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for unknown optimole

Be the first to know when new unknown vulnerabilities affecting unknown optimole are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Optimole
4.2.3 < 4.2.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/c8489eb1-e767-4b19-a7c0-124eab843d9e/

Credits

Jakub Herman WPScan