Unrated severityNVD Advisory· Published Sep 26, 2026
CVE-2026-96531
CVE-2026-96531
Description
The Optimole WordPress plugin before 4.2.13 does not escape unrecognized attributes of its video-player block before rendering them onto the block's wrapper element, allowing users with the Author role and above to store an event-handler attribute that executes scripts in the browser of any user, such as an administrator, who views the post.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.