CVE-2026-96530

Published: Ott 07, 2026 Last Modified: Ott 07, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

The Optimole WordPress plugin before 4.2.15 does not perform a capability check before exposing its stored image-optimization account data in a dashboard widget, allowing any authenticated user, including Subscribers, to read the site's third-party service credentials.

https://wpscan.com/vulnerability/2153d029-a16d-4b8c-b232-6629a6abf34b/