{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-77365/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-77365"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Optimole – Optimize Images"],"_cs_severities":["high"],"_cs_tags":["web-application","xss","wordpress","cve-2026-77365"],"_cs_type":"advisory","_cs_vendors":["Optimole"],"content_html":"\u003cp\u003eThe Optimole - Optimize Images plugin for WordPress (all versions up to and including 4.2.10) contains a critical security flaw involving insufficient input sanitization and output escaping. Specifically, the 'a' (above_fold_images) parameter fails to properly sanitize user-supplied input. This flaw allows an unauthenticated attacker to inject malicious JavaScript payloads into affected WordPress pages. When a user, such as a site administrator or privileged user, accesses the compromised page, the injected script executes within the context of their session. This vulnerability poses a significant risk for session hijacking, unauthorized administrative actions, or the redirection of site visitors to malicious domains. Organizations utilizing this plugin should upgrade to a patched version immediately upon availability or implement web application firewall rules to block suspicious input in the specified parameter.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary scripts in the browsers of users viewing the affected pages. This can lead to the theft of session cookies, account takeover of authenticated administrators, or the injection of malicious content into the site, damaging site integrity and potentially leading to further compromise of site visitors.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the Optimole plugin to the latest version, ensuring all security patches are applied.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for HTTP requests containing suspicious script tags or JavaScript event handlers within the 'a' query parameter or request body associated with the plugin.\u003c/li\u003e\n\u003cli\u003eDeploy WAF rules to validate input for the 'a' parameter, ensuring it adheres to expected data types and blocking payloads containing characters typical of XSS (e.g., \u0026lt;script\u0026gt;, javascript:, onload=).\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-28T07:12:10Z","date_published":"2026-08-28T07:12:10Z","id":"https://feed.craftedsignal.io/briefs/2026-08-optimole-xss/","summary":"The Optimole WordPress plugin is vulnerable to stored cross-site scripting due to improper sanitization of the above_fold_images parameter, allowing unauthenticated attackers to execute arbitrary JavaScript in victim browsers.","title":"Stored Cross-Site Scripting in Optimole WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-optimole-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-77365","version":"https://jsonfeed.org/version/1.1"}