Impact
Unauthenticated Cross Site Scripting in the WordPress Optimole plugin allows an attacker to inject malicious scripts that execute in the browsers of users who view affected content. This vulnerability is classified as CWE-79.
Affected Systems
The affected software is the WordPress Optimole plugin, a popular image optimization tool. Any WordPress installation running Optimole version 4.2.7 or earlier is susceptible. The description does not specify any WordPress core version requirement for exploitation.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The EPSS score of <1% shows a very low but non-zero probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker could exploit the flaw by submitting a crafted request that injects script code which is then rendered by any user who views affected content, making the vulnerability actionable without requiring privileged access.
OpenCVE Enrichment