CVE-2026-96897 PUBLISHED

Optima Express 8.5.0 - 8.7.5 - Unauthenticated Author Account Creation & Application Password Rotation via ihf_clear_cache

Assigner: WPScan
Reserved: 23.09.2026 Published: 27.09.2026 Updated: 27.09.2026

The Optima Express IDX WordPress plugin before 8.7.6 does not perform any authorisation check on one of its AJAX actions that is available to logged-out users, allowing unauthenticated attackers to force the creation of a fixed author-role account and to repeatedly rotate its application password on any connected install.

Product Status

Vendor Unknown
Product Optima Express IDX
Versions Default: unaffected
  • affected from 8.5.0 to 8.7.6 (excl.)

Credits

  • Alex Spataru finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE