CVE-2026-96899: Optima Express 8.6.0 - 8.7.5 - Author+ Stored XSS via faq_script
Published Sep 27, 2026
·Updated
The Optima Express IDX WordPress plugin before 8.7.6 does not properly neutralise a script value submitted through one of its REST endpoints before storing it and echoing it into the document head when the post is rendered, allowing users with a role as low as author to perform Stored Cross-Site Scripting attacks.
Affected Software
1 affected component
Optima Express Optima Express IDX<8.7.6
Event History
Sep 27, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which users can exploit this issue?
A user with an Author role or higher can exploit the issue by submitting a script value through one of the plugin's REST endpoints.
2
When does the injected script execute?
The submitted value is stored and later echoed into the document head when the affected post is rendered, resulting in stored cross-site scripting.
3
Which versions are affected?
Optima Express IDX versions before 8.7.6 are affected. The reported vulnerable range includes 8.6.0 through 8.7.5.