Description
The Optimole WordPress plugin before 4.2.15 does not perform a capability check before exposing its stored image-optimization account data in a dashboard widget, allowing any authenticated user, including Subscribers, to read the site's third-party service credentials.
Published: 2026-10-07
Score: n/a
EPSS: n/a
KEV: No
Impact: Information disclosure to authenticated users, including Subscribers, allowing exposure of third‑party service credentials
Action: Update Plugin
AI Analysis

Impact

The vulnerability involves a missing capability check in the Optimole WordPress plugin versions 4.0.0 through 4.2.14. This omission allows any authenticated user to view the plugin’s stored image‑optimization account data via a dashboard widget, exposing sensitive third‑party credentials. The resulting confidentiality breach could enable an attacker to hijack or misuse the connected image‑optimization service, potentially affecting the website’s integrity and operations.

Affected Systems

WordPress sites using the Optimole plugin in any version from 4.0.0 up to 4.2.14 are susceptible. The vendor is listed as Unknown:Optimole; no specific vendor name is provided in the CNA data.

Risk and Exploitability

The exploit requires only that the user be authenticated to WordPress; no elevated privileges or additional network access are needed. While the EPSS score is unavailable and the flaw is not in the CISA KEV catalog, the absence of a capability check implies a moderate to high risk of credential disclosure. Attackers who gain legitimate access, such as site subscribers, can read the widget content and obtain the service keys without further effort.

Generated by OpenCVE AI on October 7, 2026 at 07:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Optimole plugin update (4.2.15 or newer)
  • If updating is delayed, remove or disable the dashboard widget that exposes account data
  • Rotate any exposed optimizations service credentials to valid new ones

Generated by OpenCVE AI on October 7, 2026 at 07:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 07 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Optimole WordPress plugin before 4.2.15 does not perform a capability check before exposing its stored image-optimization account data in a dashboard widget, allowing any authenticated user, including Subscribers, to read the site's third-party service credentials.
Title Optimole 4.0.0 - 4.2.14 - Subscriber+ Sensitive Data Disclosure via Dashboard Widget
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-07T06:00:08.646Z

Reserved: 2026-09-23T11:20:15.394Z

Link: CVE-2026-96530

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T07:17:02.180

Modified: 2026-10-07T07:17:02.180

Link: CVE-2026-96530

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T08:00:12Z

Weaknesses