PT-2026-98396 · WordPress · Optima Express Idx
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Optima Express IDX versions prior to 8.7.6
Description
An issue allows unauthenticated attackers to escalate the privileges of a pre-registered account to the Author role. This occurs because the
provisionBlogCredentials() function in iHomefinderAdmin.php is accessible via the wp ajax nopriv ihf clear cache AJAX action through a specific call chain involving iHomefinderAjaxHandler::clearCache(), activateAuthenticationToken(), and getAuthenticationInfo(). The function lacks capability checks, nonce verification, and ownership validation, unconditionally assigning the Author role to any account matching the hard-coded login optima-express via get user by('login','optima-express'). Successful exploitation grants publish posts, upload files, and edit published posts capabilities, as well as access to the /wp-json/optima-express/v1/blog-post REST endpoint. This requires open user registration to be enabled and the attacker to register the optima-express username before the plugin provisions it.Recommendations
Update Optima Express IDX to version 8.7.6 or later.
Disable open user registration on the WordPress site to prevent unauthorized account creation.
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Optima Express Idx