WordPress Plugin Vulnerabilities

Optima Express 8.6.0 - 8.7.5 - Author+ Stored XSS via faq_script

Description

The plugin does not properly neutralise a script value submitted through one of its REST endpoints before storing it and echoing it into the document head when the post is rendered, allowing users with a role as low as author to perform Stored Cross-Site Scripting attacks.

Proof of Concept

Affects Plugins

Fixed in 8.7.6

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Usama Arshad
Submitter
Usama Arshad
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-09-25 (about 2 days ago)
Added
2026-09-25 (about 1 day ago)
Last Updated
2026-09-25 (about 1 day ago)

Other