CVE-2026-93901: CWE-269 Improper Privilege Management in ihomefinder Optima Express IDX
The Optima Express IDX plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 8.7.5. This is due to the `provisionBlogCredentials()` function in `iHomefinderAdmin.php` being reachable via the `wp_ajax_nopriv_ihf_clear_cache` AJAX action — through the call chain `iHomefinderAjaxHandler::clearCache()` → `activateAuthenticationToken()` → `getAuthenticationInfo()` → `provisionBlogCredentials()` — with no capability check, nonce verification, or ownership validation, and the function unconditionally calling `$user->set_role('author')` on whichever WordPress account matches the hard-coded login `optima-express` via `get_user_by('login', 'optima-express')`. This makes it possible for unauthenticated attackers to escalate a pre-registered `optima-express` account to the Author role, gaining `publish_posts`, `upload_files`, and `edit_published_posts` capabilities, including access to the plugin's own `/wp-json/optima-express/v1/blog-post` REST endpoint. Exploitation requires open user registration to be enabled on the target site, and the attacker must register the `optima-express` username before the plugin has had the opportunity to provision that login for its own integration account.
AI Analysis
Technical Summary
CVE-2026-93901 is a privilege escalation vulnerability in the Optima Express IDX plugin for WordPress (versions <= 8.7.5). The vulnerability arises because the 'provisionBlogCredentials()' function in 'iHomefinderAdmin.php' can be triggered via the 'wp_ajax_nopriv_ihf_clear_cache' AJAX action without any capability checks, nonce verification, or ownership validation. This function unconditionally sets the WordPress user with login 'optima-express' to the Author role. An unauthenticated attacker can exploit this by registering the 'optima-express' username (if open registration is enabled) before the plugin provisions it, thereby gaining elevated privileges including access to the plugin's REST endpoint.
Potential Impact
An attacker can escalate privileges of a WordPress user account named 'optima-express' to the Author role, granting the ability to publish posts, upload files, and edit published posts. This can lead to unauthorized content publication and potential further compromise via the plugin's REST API. The attack requires open user registration and pre-registration of the 'optima-express' username by the attacker.
Mitigation Recommendations
No official patch or fix is currently documented. Users should verify if a vendor advisory or update is available. Until then, mitigation includes disabling open user registration on the WordPress site to prevent attacker registration of the 'optima-express' username. Monitor for updates from the vendor and apply official patches once released.
CVE-2026-93901: CWE-269 Improper Privilege Management in ihomefinder Optima Express IDX
Description
The Optima Express IDX plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 8.7.5. This is due to the `provisionBlogCredentials()` function in `iHomefinderAdmin.php` being reachable via the `wp_ajax_nopriv_ihf_clear_cache` AJAX action — through the call chain `iHomefinderAjaxHandler::clearCache()` → `activateAuthenticationToken()` → `getAuthenticationInfo()` → `provisionBlogCredentials()` — with no capability check, nonce verification, or ownership validation, and the function unconditionally calling `$user->set_role('author')` on whichever WordPress account matches the hard-coded login `optima-express` via `get_user_by('login', 'optima-express')`. This makes it possible for unauthenticated attackers to escalate a pre-registered `optima-express` account to the Author role, gaining `publish_posts`, `upload_files`, and `edit_published_posts` capabilities, including access to the plugin's own `/wp-json/optima-express/v1/blog-post` REST endpoint. Exploitation requires open user registration to be enabled on the target site, and the attacker must register the `optima-express` username before the plugin has had the opportunity to provision that login for its own integration account.
CVSS v3.1
Score 7.3high
Affected software
ihomefinder
Optima Express IDX
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-93901 is a privilege escalation vulnerability in the Optima Express IDX plugin for WordPress (versions <= 8.7.5). The vulnerability arises because the 'provisionBlogCredentials()' function in 'iHomefinderAdmin.php' can be triggered via the 'wp_ajax_nopriv_ihf_clear_cache' AJAX action without any capability checks, nonce verification, or ownership validation. This function unconditionally sets the WordPress user with login 'optima-express' to the Author role. An unauthenticated attacker can exploit this by registering the 'optima-express' username (if open registration is enabled) before the plugin provisions it, thereby gaining elevated privileges including access to the plugin's REST endpoint.
Potential Impact
An attacker can escalate privileges of a WordPress user account named 'optima-express' to the Author role, granting the ability to publish posts, upload files, and edit published posts. This can lead to unauthorized content publication and potential further compromise via the plugin's REST API. The attack requires open user registration and pre-registration of the 'optima-express' username by the attacker.
Mitigation Recommendations
No official patch or fix is currently documented. Users should verify if a vendor advisory or update is available. Until then, mitigation includes disabling open user registration on the WordPress site to prevent attacker registration of the 'optima-express' username. Monitor for updates from the vendor and apply official patches once released.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Wordfence
- Date Reserved
- 2026-09-18T20:38:39.058Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab62746f7a7c541068154d7
Added to database: 09/25/2026, 07:48:22 UTC
Last enriched: 09/25/2026, 08:02:59 UTC
Last updated: 09/26/2026, 02:48:28 UTC
Views: 20
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.