Impact
The Optimole – Optimize Images plugin for WordPress is vulnerable to stored cross‑site scripting. Because the plugin fails to sanitize or escape the 'a' (above_fold_images) parameter, an unauthenticated attacker can inject arbitrary JavaScript that will run whenever a user loads a page containing the injected value. This flaw allows the attacker to execute scripts in a victim’s browser, potentially leading to session hijacking, defacement or redirection to malicious sites.
Affected Systems
All installations of the Optimole WordPress plugin up to and including version 4.2.10 are affected. The vulnerability exists in the plugin’s core files that handle the 'a' parameter and in the PageProfiler profile code. WordPress site owners using this plugin should check the plugin version and upgrade to a fixed release.
Risk and Exploitability
The vulnerability has a CVSS score of 7.2 and is listed as not currently in the CISA KEV catalog. No EPSS score is available, implying limited publicly known exploitation attempts. Attackers can exploit the flaw without any authentication by sending crafted requests that set the 'a' parameter and then trick users to view the affected page. The impact is limited to the browsing context of users who view the affected content and can spread quickly through shared links or social engineering.
OpenCVE Enrichment