CVE-2026-96899: Unknown Optima Express Idx

Medium severity, CVSS 6.8. EPSS: 0.2% chance of exploitation in the next 30 days.

The Optima Express IDX WordPress plugin before 8.7.6 does not properly neutralise a script value submitted through one of its REST endpoints before storing it and echoing it into the document head when the post is rendered, allowing users with a role as low as author to perform Stored Cross-Site Scripting attacks.

Affected products

  • Unknown Optima Express Idx: from 8.6.0, before 8.7.6 (fixed in 8.7.6)

Published 2026-09-27. Last modified 2026-09-28.