CVE-2026-84829: Optimole < 4.2.12 - Unauthenticated Stored XSS via Srcset Descriptor Parameter
The Optimole WordPress plugin before 4.2.12 does not properly escape a user supplied value before using it to build an image tag attribute, allowing unauthenticated users to inject arbitrary attributes into pages served to every visitor, which leads to Stored Cross-Site Scripting.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
The issue can be exploited by unauthenticated users; no authenticated WordPress account is required. Successful exploitation can inject arbitrary attributes into pages viewed by site visitors.
Which plugin versions are affected?
Optimole versions before 4.2.12 are affected. Version 4.2.12 is the first version identified as not affected by the provided data.
What is the impact on visitors?
The injected content is stored and served to every visitor of affected pages. This can result in cross-site scripting executing in visitors' browsers.