GHSA-xprw-377p-8v85MediumCVSS 6.8

The Optima Express IDX WordPress plugin before 8.7.6 does not properly neutralise a script value...

Published
September 27, 2026
Last Modified
September 28, 2026

🔗 CVE IDs covered (1)

📋 Description

The Optima Express IDX WordPress plugin before 8.7.6 does not properly neutralise a script value submitted through one of its REST endpoints before storing it and echoing it into the document head when the post is rendered, allowing users with a role as low as author to perform Stored Cross-Site Scripting attacks.

🔗 References (3)