WordPress Plugin Vulnerabilities

Optima Express 8.5.0 - 8.7.5 - Unauthenticated Author Account Creation & Application Password Rotation via ihf_clear_cache

Description

The plugin does not perform any authorisation check on one of its AJAX actions that is available to logged-out users, allowing unauthenticated attackers to force the creation of a fixed author-role account and to repeatedly rotate its application password on any connected install.

Proof of Concept

Affects Plugins

Fixed in 8.7.6

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Alex Spataru
Submitter
Alex Spataru
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-09-25 (about 2 days ago)
Added
2026-09-25 (about 1 day ago)
Last Updated
2026-09-25 (about 1 day ago)

Other