CVE-2026-96531: Optimole 4.0.0 - 4.2.12 - Author+ Stored XSS via Video Player Block
Published Sep 26, 2026
·Updated
The Optimole WordPress plugin before 4.2.13 does not escape unrecognized attributes of its video-player block before rendering them onto the block's wrapper element, allowing users with the Author role and above to store an event-handler attribute that executes scripts in the browser of any user, such as an administrator, who views the post.
Affected Software
1 affected component
Optimole Optimole WordPress plugin>=4.0.0<=4.2.12
Event History
Sep 26, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Which users can exploit this issue, and who is at risk from the stored script?
A user with the Author role or higher can store a malicious event-handler attribute in a video-player block. The script executes in the browser of any user who views the affected post, including administrators.
2
Which plugin versions are affected and what version fixes the issue?
Optimole versions 4.0.0 through 4.2.12 are affected. Version 4.2.13 and later are not affected by the described issue.