Impact
The vulnerability arises because the Optima Express IDX WordPress plugin does not sanitize a script value that is submitted via its REST endpoints. The unsanitized value is stored and later echoed into the document head when the post is rendered. An attacker with the role of author can exploit this to execute arbitrary JavaScript in the browsers of visitors who view the affected content, resulting in stolen credentials, session hijacking, or defacement.
Affected Systems
All installations of the Optima Express IDX plugin for WordPress with versions from 8.6.0 up through 8.7.5 are affected. The vendor, listed only as Unknown:Optima Express IDX, does not provide further product subdivision. Site administrators who deploy this plugin should verify the installed version; only versions earlier than 8.7.6 are vulnerable.
Risk and Exploitability
There is no CVSS score provided in the data, but the EPSS value is unknown and the vulnerability is not included in the CISA KEV catalog, indicating that it has not yet been widely exploited in the wild. Nonetheless, the attack is a remote stored XSS that requires an authenticated author, which is a low‑privilege role commonly granted to content contributors. Because the payload is embedded in the page head, any visitor can execute it, creating a high‑impact risk. The absence of a published exploit does not diminish the potential danger; site owners should treat the vulnerability as high severity and remediate promptly.
OpenCVE Enrichment