CVE-2026-96899: Optima Express 8.6.0 - 8.7.5 - Author+ Stored XSS via faq_script

Published Sep 27, 2026
·
Updated

The Optima Express IDX WordPress plugin before 8.7.6 does not properly neutralise a script value submitted through one of its REST endpoints before storing it and echoing it into the document head when the post is rendered, allowing users with a role as low as author to perform Stored Cross-Site Scripting attacks.

Affected Software

1 affected component
Optima Express Optima Express IDX<8.7.6

Event History

Sep 27, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which users can exploit this issue?

A user with an Author role or higher can exploit the issue by submitting a script value through one of the plugin's REST endpoints.

2

When does the injected script execute?

The submitted value is stored and later echoed into the document head when the affected post is rendered, resulting in stored cross-site scripting.

3

Which versions are affected?

Optima Express IDX versions before 8.7.6 are affected. The reported vulnerable range includes 8.6.0 through 8.7.5.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203