CVE-2026-96530: Unknown Optimole

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

The Optimole WordPress plugin before 4.2.15 does not perform a capability check before exposing its stored image-optimization account data in a dashboard widget, allowing any authenticated user, including Subscribers, to read the site's third-party service credentials.

Affected products

  • Unknown Optimole: from 4.0.0, before 4.2.15 (fixed in 4.2.15)

Published 2026-10-07. Last modified 2026-10-07.