CVE-2026-96531: Unknown Optimole
Medium severity, CVSS 6.8. EPSS: 0.2% chance of exploitation in the next 30 days.
The Optimole WordPress plugin before 4.2.13 does not escape unrecognized attributes of its video-player block before rendering them onto the block's wrapper element, allowing users with the Author role and above to store an event-handler attribute that executes scripts in the browser of any user, such as an administrator, who views the post.
Affected products
- Unknown Optimole: from 4.0.0, before 4.2.13 (fixed in 4.2.13)
Published 2026-09-26. Last modified 2026-09-28.