Description
Subscriber Broken Access Control in Optimole <= 4.2.14 versions.
Published: 2026-09-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access to Protected Content
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a broken access control flaw that allows individuals who should be unable to view certain subscriber content to gain access. This weakness is represented by CWE-862. An attacker could read or download protected media files or user data that the plugin is intended to hide from non‑authorized visitors. The impact is limited to confidentiality loss; integrity and availability are not directly affected unless the attacker forces additional actions using the accessed content.

Affected Systems

Any WordPress site running the Optimole image optimization plugin version 4.2.14 or earlier is affected. The vulnerability exists within the plugin’s access validation layer and can affect all embedded endpoints that serve image data to subscribers. Sites using earlier versions without the latest security build must be upgraded.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity risk. EPSS is not available, so the likelihood of exploitation is unclear but not considered negligible. The vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation reports. Attackers would need to identify a target site using the vulnerable plugin, and the flaw appears to be exploitable remotely via web requests that bypass the subscriber check. No special privileges or credentials appear required beyond what an attacker can obtain through normal web interactions.

Generated by OpenCVE AI on September 30, 2026 at 19:49 UTC.

Remediation

Vendor Solution

Update the WordPress Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin to the latest available version (at least 4.2.15).


OpenCVE Recommended Actions

  • Install the latest version of the Optimole plugin (4.2.15 or newer) to replace the vulnerable code.
  • If an immediate upgrade is not feasible, remove the plugin entirely or disable its image serving features until a patch is applied.
  • After updating, scan the site for any cached or moved content that may have been exposed and revoke access to those assets as necessary.

Generated by OpenCVE AI on September 30, 2026 at 19:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description Subscriber Broken Access Control in Optimole <= 4.2.14 versions.
Title WordPress Optimole plugin <= 4.2.14 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-30T17:59:55.236Z

Reserved: 2026-09-29T00:15:56.340Z

Link: CVE-2026-102375

cve-icon Vulnrichment

Updated: 2026-09-30T17:59:18.024Z

cve-icon NVD

Status : Deferred

Published: 2026-09-30T18:18:14.040

Modified: 2026-09-30T19:04:41.917

Link: CVE-2026-102375

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T20:00:11Z

Weaknesses