CVE-2026-96899 PUBLISHED

Optima Express 8.6.0 - 8.7.5 - Author+ Stored XSS via faq_script

Assigner: WPScan
Reserved: 23.09.2026 Published: 27.09.2026 Updated: 27.09.2026

The Optima Express IDX WordPress plugin before 8.7.6 does not properly neutralise a script value submitted through one of its REST endpoints before storing it and echoing it into the document head when the post is rendered, allowing users with a role as low as author to perform Stored Cross-Site Scripting attacks.

Product Status

Vendor Unknown
Product Optima Express IDX
Versions Default: unaffected
  • affected from 8.6.0 to 8.7.6 (excl.)

Credits

  • Usama Arshad finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE