Vendor
high
advisory
Stored Cross-Site Scripting in Optimole WordPress Plugin
1 rule 1 TTP 1 CVEThe Optimole WordPress plugin is vulnerable to stored cross-site scripting due to improper sanitization of the above_fold_images parameter, allowing unauthenticated attackers to execute arbitrary JavaScript in victim browsers.
Optimole – Optimize Images
web-application
xss
wordpress
cve-2026-77365
1r
1t
1c
high
advisory
Optimole WordPress Plugin Stored XSS Vulnerability
2 rules 1 TTP 1 CVEThe Optimole WordPress plugin before version 4.2.3 is vulnerable to stored cross-site scripting (XSS) due to insufficient input sanitization and output escaping on the 's' parameter (srcset descriptor) in the unauthenticated /wp-json/optimole/v1/optimizations REST endpoint, allowing unauthenticated attackers to inject arbitrary web scripts.
Optimole WordPress Plugin
wordpress
xss
plugin
cve-2026-5217
2r
1t
1c