CVE-2026-96531 PUBLISHED

Optimole 4.0.0 - 4.2.12 - Author+ Stored XSS via Video Player Block

Assigner: WPScan
Reserved: 23.09.2026 Published: 26.09.2026 Updated: 26.09.2026

The Optimole WordPress plugin before 4.2.13 does not escape unrecognized attributes of its video-player block before rendering them onto the block's wrapper element, allowing users with the Author role and above to store an event-handler attribute that executes scripts in the browser of any user, such as an administrator, who views the post.

Product Status

Vendor Unknown
Product Optimole
Versions Default: unaffected
  • affected from 4.0.0 to 4.2.13 (excl.)

Credits

  • Dmitrii Ignatyev finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE