CVE-2026-96530: CWE-200 Information Exposure in Optimole
Description
A vulnerability in the Optimole WordPress plugin before version 4.2.15 allows any authenticated user, including those with Subscriber roles, to access sensitive image-optimization account credentials via a dashboard widget. This occurs because the plugin does not perform proper capability checks before exposing this data.
Affected software
Optimole
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-96530 is an information exposure vulnerability (CWE-200) in the Optimole WordPress plugin versions 4.0.0 up to but not including 4.2.15. The plugin fails to verify user capabilities before displaying stored third-party service credentials in a dashboard widget. As a result, any authenticated user, regardless of privilege level, can read these sensitive credentials, potentially compromising the site's integration with the third-party image optimization service.
Potential Impact
The vulnerability allows unauthorized disclosure of sensitive third-party service credentials to any authenticated user, including low-privilege roles such as Subscribers. This exposure could lead to misuse of the service account, unauthorized access to the image optimization service, or further compromise depending on the credentials' privileges. There is no indication of active exploitation in the wild.
Mitigation Recommendations
Upgrade the Optimole plugin to version 4.2.15 or later where this issue is fixed. Since the vulnerability is due to missing capability checks, the official fix involves proper permission validation before displaying sensitive data. Patch status is not explicitly stated but the affected versions are prior to 4.2.15, indicating the fix is included in 4.2.15. Users should update promptly to remediate this exposure.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-09-23T11:20:15.394Z
- State
- PUBLISHED
Threat ID: 6ac5e7da2cdf04f65621e247
Added to database: 10/07/2026, 06:34:02 UTC
Last enriched: 10/07/2026, 06:48:24 UTC
Last updated: 10/07/2026, 06:49:15 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.