{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/ihomefinder/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ihomefinder:optima_express_idx:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-93901"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Optima Express IDX (\u003c= 8.7.5)"],"_cs_severities":["high"],"_cs_tags":["wordpress","privilege-escalation","web-application"],"_cs_type":"advisory","_cs_vendors":["iHomefinder"],"content_html":"\u003cp\u003eThe Optima Express IDX plugin for WordPress, in all versions up to and including 8.7.5, contains a critical privilege escalation vulnerability. The flaw exists within the \u003ccode\u003eprovisionBlogCredentials()\u003c/code\u003e function located in \u003ccode\u003eiHomefinderAdmin.php\u003c/code\u003e. This function is reachable via the \u003ccode\u003ewp_ajax_nopriv_ihf_clear_cache\u003c/code\u003e AJAX action, which lacks necessary capability checks, nonce verification, and ownership validation.\u003c/p\u003e\n\u003cp\u003eThe exploitation path follows the chain \u003ccode\u003eiHomefinderAjaxHandler::clearCache()\u003c/code\u003e to \u003ccode\u003eactivateAuthenticationToken()\u003c/code\u003e, \u003ccode\u003egetAuthenticationInfo()\u003c/code\u003e, and finally \u003ccode\u003eprovisionBlogCredentials()\u003c/code\u003e. The function unconditionally executes \u003ccode\u003e$user-\u0026gt;set_role('author')\u003c/code\u003e for any user account matching the login \u003ccode\u003eoptima-express\u003c/code\u003e. If a WordPress site has open user registration enabled, an attacker can register this specific username before the plugin performs its internal integration setup. By doing so, the attacker successfully gains 'author' privileges, including the ability to publish and edit posts, and gains unauthorized access to the \u003ccode\u003e/wp-json/optima-express/v1/blog-post\u003c/code\u003e REST API endpoint.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker identifies a WordPress site with the Optima Express IDX plugin installed and open registration enabled.\u003c/li\u003e\n\u003cli\u003eThe attacker registers a new WordPress user account using the username \u003ccode\u003eoptima-express\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a request to the \u003ccode\u003ewp-admin/admin-ajax.php\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eThe attacker specifies the \u003ccode\u003eaction\u003c/code\u003e parameter as \u003ccode\u003eihf_clear_cache\u003c/code\u003e to trigger the vulnerable code path.\u003c/li\u003e\n\u003cli\u003eThe plugin's \u003ccode\u003eiHomefinderAjaxHandler::clearCache()\u003c/code\u003e method is invoked by the WordPress AJAX handler.\u003c/li\u003e\n\u003cli\u003eThe execution chain proceeds to \u003ccode\u003eprovisionBlogCredentials()\u003c/code\u003e, which identifies the attacker-controlled \u003ccode\u003eoptima-express\u003c/code\u003e account.\u003c/li\u003e\n\u003cli\u003eThe plugin executes \u003ccode\u003e$user-\u0026gt;set_role('author')\u003c/code\u003e on the attacker's account.\u003c/li\u003e\n\u003cli\u003eThe attacker now possesses 'author' level permissions, including REST API access for blog post management.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in unauthorized privilege escalation to the Author role on the affected WordPress site. This grants the attacker the ability to create, edit, and publish posts, manage media uploads, and access specific plugin-restricted REST endpoints. This vulnerability poses a significant risk to site integrity and content management for any WordPress installation that allows public user registration while using the Optima Express IDX plugin.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eImmediately update the Optima Express IDX plugin to a version beyond 8.7.5 if a patch is available.\u003c/li\u003e\n\u003cli\u003eIf an update is not currently available, disable the open user registration feature in WordPress settings (\u003ccode\u003eSettings \u0026gt; General \u0026gt; Membership\u003c/code\u003e) to prevent attackers from registering the \u003ccode\u003eoptima-express\u003c/code\u003e username.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious POST requests to \u003ccode\u003eadmin-ajax.php\u003c/code\u003e where \u003ccode\u003eaction=ihf_clear_cache\u003c/code\u003e.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-25T10:52:34Z","date_published":"2026-09-25T10:52:34Z","id":"https://feed.craftedsignal.io/briefs/2026-09-optima-express-privesc/","summary":"An unauthenticated privilege escalation vulnerability (CVE-2026-93901) in the Optima Express IDX plugin allows attackers to elevate a pre-registered 'optima-express' user account to the Author role.","title":"Privilege Escalation in Optima Express IDX WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-optima-express-privesc/"}],"language":"en","title":"CraftedSignal Threat Feed - IHomefinder","version":"https://jsonfeed.org/version/1.1"}