PT-2026-99505 · WordPress · Optima Express Idx
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Optima Express IDX WordPress plugin versions prior to 8.7.6
Description
An authorization check is missing in an AJAX action available to logged-out users. This allows unauthenticated attackers to force the creation of an account with a fixed author role and repeatedly rotate its application password on any connected installation.
Recommendations
Update Optima Express IDX WordPress plugin to version 8.7.6 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Optima Express Idx