WordPress Plugin Vulnerabilities

Optimole < 4.2.12 - Unauthenticated Stored XSS via Srcset Descriptor Parameter

Description

The plugin does not properly escape a user supplied value before using it to build an image tag attribute, allowing unauthenticated users to inject arbitrary attributes into pages served to every visitor, which leads to Stored Cross-Site Scripting.
The escaping added in 4.2.3 for CVE-2026-5217 does not cover the context the value is finally used in, so releases from 4.2.3 onwards remain affected.

Proof of Concept

Affects Plugins

Fixed in 4.2.12

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
Jakub Herman
Submitter
Jakub Herman
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-09-14 (about 2 days ago)
Added
2026-09-14 (about 1 day ago)
Last Updated
2026-09-14 (about 1 day ago)

Other