Impact
The vulnerability involves a missing capability check in the Optimole WordPress plugin versions 4.0.0 through 4.2.14. This omission allows any authenticated user to view the plugin’s stored image‑optimization account data via a dashboard widget, exposing sensitive third‑party credentials. The resulting confidentiality breach could enable an attacker to hijack or misuse the connected image‑optimization service, potentially affecting the website’s integrity and operations.
Affected Systems
WordPress sites using the Optimole plugin in any version from 4.0.0 up to 4.2.14 are susceptible. The vendor is listed as Unknown:Optimole; no specific vendor name is provided in the CNA data.
Risk and Exploitability
The exploit requires only that the user be authenticated to WordPress; no elevated privileges or additional network access are needed. While the EPSS score is unavailable and the flaw is not in the CISA KEV catalog, the absence of a capability check implies a moderate to high risk of credential disclosure. Attackers who gain legitimate access, such as site subscribers, can read the widget content and obtain the service keys without further effort.
OpenCVE Enrichment