Image Optimization by Optimole – Lazy Load, CDN, Convert WebP & AVIF, CVE-2026-96531
- CVE, Research URL
- Home page URL
-
Security reports for Image Optimization by Optimole – Lazy Load, CDN, Convert WebP & AVIF
- Published on
- Sep 26, 2026
- Research Description
- The Optimole WordPress plugin before 4.2.13 does not escape unrecognized attributes of its video-player block before rendering them onto the block's wrapper element, allowing users with the Author role and above to store an event-handler attribute that executes scripts in the browser of any user, such as an administrator, who views the post.
- Affected versions
-
Min 4.0.0, max 4.2.13.
- Status
-
vulnerable