PT-2026-99251 · WordPress · Optimole
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Optimole WordPress plugin versions prior to 4.2.13
Description
The plugin fails to escape unrecognized attributes within its video-player block before rendering them onto the block's wrapper element. This allows users with the Author role or higher to inject an event-handler attribute, enabling the execution of arbitrary scripts in the browser of any user, including administrators, who views the affected post.
Recommendations
Update the Optimole WordPress plugin to version 4.2.13 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Optimole