CVE-2026-96899
Received Received - Intake

Stored XSS in Optima Express IDX WordPress Plugin

Vulnerability report for CVE-2026-96899, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-27

Last updated on: 2026-09-27

Assigner: WPScan

Description

The Optima Express IDX WordPress plugin before 8.7.6 does not properly neutralise a script value submitted through one of its REST endpoints before storing it and echoing it into the document head when the post is rendered, allowing users with a role as low as author to perform Stored Cross-Site Scripting attacks.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-27
Last Modified
2026-09-27
Generated
2026-09-27
AI Q&A
2026-09-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
optima_express optima_express_idx to 8.7.5 (inc)
optima_express optima_express_idx 8.7.6

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Optima Express IDX WordPress plugin before version 8.7.6 has a stored cross-site scripting (XSS) vulnerability. This means user-supplied input through a REST endpoint is not properly neutralized before being stored and later rendered in the document head when a post is viewed. Attackers with an author role or higher can exploit this to inject malicious scripts.

Detection Guidance

Check if the Optima Express plugin version is between 8.6.0 and 8.7.5. Use WordPress commands like 'wp plugin list' to verify installed versions. Inspect REST endpoints for unauthorized script injections in post content or metadata.

Impact Analysis

An attacker could steal session cookies, redirect users to malicious sites, or perform actions on their behalf. This could lead to unauthorized access to sensitive data, account takeovers, or defacement of the website. Users with author-level access or higher are the primary threat actors.

Compliance Impact

This vulnerability could lead to unauthorized access or exposure of user data, violating GDPR's data protection principles or HIPAA's security requirements. Organizations may face fines or penalties for failing to protect user data adequately.

Mitigation Strategies

Update the Optima Express plugin to version 8.7.6 or later immediately. Remove or restrict author-level users' ability to submit untrusted input via REST endpoints until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-96899. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart