CVE-2026-96530: Unknown Optimole
Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.
The Optimole WordPress plugin before 4.2.15 does not perform a capability check before exposing its stored image-optimization account data in a dashboard widget, allowing any authenticated user, including Subscribers, to read the site's third-party service credentials.
Affected products
- Unknown Optimole: from 4.0.0, before 4.2.15 (fixed in 4.2.15)
Published 2026-10-07. Last modified 2026-10-07.