GHSA-q3p9-mmwf-qgrcMediumCVSS 6.5

The Optimole WordPress plugin before 4.2.15 does not perform a capability check before exposing...

Published
October 7, 2026
Last Modified
October 7, 2026

🔗 CVE IDs covered (1)

📋 Description

The Optimole WordPress plugin before 4.2.15 does not perform a capability check before exposing its stored image-optimization account data in a dashboard widget, allowing any authenticated user, including Subscribers, to read the site's third-party service credentials.

🔗 References (3)