{"id":"CVE-2026-96530","title":"The Optimole  WordPress plugin before 4.2.15 does not perform a capability check before exposing its stored image-optimization account data in a dashboard widget, allowing any authenticated user, including Subscribers, to read the site's…","summary":"The Optimole  WordPress plugin before 4.2.15 does not perform a capability check before exposing its stored image-optimization account data in a dashboard widget, allowing any authenticated user, including Subscribers, to read the site's…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-200"],"product":"Optimole","affected":["Optimole >= 4.0.0 < 4.2.15"],"published":"2026-10-07","updated":"2026-10-07","sourceUpdated":"2026-10-07T10:17:42.487","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-96530","references":[{"url":"https://wpscan.com/vulnerability/2153d029-a16d-4b8c-b232-6629a6abf34b/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-10-07T09:51:21.044748Z"},"ingestedAt":"2026-10-07T08:20:03.944Z","slug":"CVE-2026-96530","body":"## Overview\n\nThe Optimole  WordPress plugin before 4.2.15 does not perform a capability check before exposing its stored image-optimization account data in a dashboard widget, allowing any authenticated user, including Subscribers, to read the site's third-party service credentials.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":217397,"id":"CVE-2026-96530","ts":1791368789402,"field":"cvss","old":null,"new":"6.5"},{"seq":217396,"id":"CVE-2026-96530","ts":1791368789402,"field":"severity","old":"none","new":"medium"}]}