CVE-2026-102375: WordPress Optimole plugin <= 4.2.14 - Broken Access Control vulnerability
Published Sep 30, 2026
·Updated
Subscriber Broken Access Control in Optimole <= 4.2.14 versions.
Affected Software
1 affected component
Optimole Optimole plugin<=4.2.14
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization pluginto a version that resolves this vulnerability.Fixed in 4.2.15
Event History
Sep 30, 2026
CVE Published
via MITRE·05:39 PM
Data Sourced
via MITRE·05:39 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An authenticated user with Subscriber-level access can exploit the broken access control. The attack can be performed over the network and does not require user interaction.
2
What is the potential impact?
The vulnerability has high confidentiality impact. The available data does not indicate integrity or availability impact.
3
Which versions are affected?
Optimole plugin versions up to and including 4.2.14 are affected.