CVE-2026-96530: Optimole 4.0.0 - 4.2.14 - Subscriber+ Sensitive Data Disclosure via Dashboard Widget
Published Oct 7, 2026
·Updated
The Optimole WordPress plugin before 4.2.15 does not perform a capability check before exposing its stored image-optimization account data in a dashboard widget, allowing any authenticated user, including Subscribers, to read the site's third-party service credentials.
Affected Software
1 affected component
Optimole Optimole WordPress plugin>=4.0.0<=4.2.14
Event History
Oct 7, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness