CVE-2026-84829: CWE-79 Cross-Site Scripting (XSS) in Optimole
The Optimole WordPress plugin before 4.2.12 does not properly escape a user supplied value before using it to build an image tag attribute, allowing unauthenticated users to inject arbitrary attributes into pages served to every visitor, which leads to Stored Cross-Site Scripting.
AI Analysis
Technical Summary
CVE-2026-84829 is a stored cross-site scripting vulnerability in the Optimole WordPress plugin. Versions >=4.2.3 and <4.2.12 do not properly escape user input before using it in image tag attributes. This flaw allows unauthenticated users to inject arbitrary attributes into pages, leading to stored XSS that affects every visitor to the site.
Potential Impact
An attacker can inject malicious attributes into image tags that are stored and served to all visitors, potentially enabling execution of arbitrary scripts in the context of the affected website. This can lead to session hijacking, defacement, or other client-side attacks against users of the site.
Mitigation Recommendations
A fix is available in Optimole version 4.2.12. Users should upgrade to version 4.2.12 or later to remediate this vulnerability.
CVE-2026-84829: CWE-79 Cross-Site Scripting (XSS) in Optimole
Description
The Optimole WordPress plugin before 4.2.12 does not properly escape a user supplied value before using it to build an image tag attribute, allowing unauthenticated users to inject arbitrary attributes into pages served to every visitor, which leads to Stored Cross-Site Scripting.
Affected software
Optimole
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-84829 is a stored cross-site scripting vulnerability in the Optimole WordPress plugin. Versions >=4.2.3 and <4.2.12 do not properly escape user input before using it in image tag attributes. This flaw allows unauthenticated users to inject arbitrary attributes into pages, leading to stored XSS that affects every visitor to the site.
Potential Impact
An attacker can inject malicious attributes into image tags that are stored and served to all visitors, potentially enabling execution of arbitrary scripts in the context of the affected website. This can lead to session hijacking, defacement, or other client-side attacks against users of the site.
Mitigation Recommendations
A fix is available in Optimole version 4.2.12. Users should upgrade to version 4.2.12 or later to remediate this vulnerability.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-09-02T11:30:12.919Z
- State
- PUBLISHED
Threat ID: 6aaa32e055bf5e2cf517fb30
Added to database: 09/16/2026, 06:10:40 UTC
Last enriched: 09/16/2026, 06:31:37 UTC
Last updated: 09/17/2026, 03:26:25 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.