๐Ÿ” CVE Alert

CVE-2026-96531

UNKNOWN 0.0

Optimole 4.0.0 - 4.2.12 - Author+ Stored XSS via Video Player Block

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Optimole WordPress plugin before 4.2.13 does not escape unrecognized attributes of its video-player block before rendering them onto the block's wrapper element, allowing users with the Author role and above to store an event-handler attribute that executes scripts in the browser of any user, such as an administrator, who views the post.

Vendor unknown
Product optimole
Published Sep 26, 2026
Stay Ahead of the Next One

Get instant alerts for unknown optimole

Be the first to know when new unknown vulnerabilities affecting unknown optimole are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Optimole
4.0.0 < 4.2.13

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/15ad5748-8c2b-4c60-9818-57790f7033c7/

Credits

Dmitrii Ignatyev WPScan