WordPress Plugin Vulnerabilities

Optimole 4.0.0 - 4.2.12 - Author+ Stored XSS via Video Player Block

Description

The plugin does not escape unrecognized attributes of its video-player block before rendering them onto the block's wrapper element, allowing users with the Author role and above to store an event-handler attribute that executes scripts in the browser of any user, such as an administrator, who views the post.

Proof of Concept

Affects Plugins

Fixed in 4.2.13

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Dmitrii Ignatyev
Submitter
Dmitrii Ignatyev
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-09-24 (about 2 days ago)
Added
2026-09-24 (about 1 day ago)
Last Updated
2026-09-24 (about 1 day ago)

Other