PT-2026-98396 · WordPress · Optima Express Idx

·

CVE-2026-93901

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Optima Express IDX versions prior to 8.7.6
Description An issue allows unauthenticated attackers to escalate the privileges of a pre-registered account to the Author role. This occurs because the provisionBlogCredentials() function in iHomefinderAdmin.php is accessible via the wp ajax nopriv ihf clear cache AJAX action through a specific call chain involving iHomefinderAjaxHandler::clearCache(), activateAuthenticationToken(), and getAuthenticationInfo(). The function lacks capability checks, nonce verification, and ownership validation, unconditionally assigning the Author role to any account matching the hard-coded login optima-express via get user by('login','optima-express'). Successful exploitation grants publish posts, upload files, and edit published posts capabilities, as well as access to the /wp-json/optima-express/v1/blog-post REST endpoint. This requires open user registration to be enabled and the attacker to register the optima-express username before the plugin provisions it.
Recommendations Update Optima Express IDX to version 8.7.6 or later. Disable open user registration on the WordPress site to prevent unauthorized account creation.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93901

Affected Products

Optima Express Idx