{"id":"CVE-2026-96531","title":"The Optimole  WordPress plugin before 4.2.13 does not escape unrecognized attributes of its video-player block before rendering them onto the block's wrapper element, allowing users with the Author role and above to store an event-handle…","summary":"The Optimole  WordPress plugin before 4.2.13 does not escape unrecognized attributes of its video-player block before rendering them onto the block's wrapper element, allowing users with the Author role and above to store an event-handle…","severity":"none","cwe":["CWE-79"],"product":"Optimole","affected":["Optimole >= 4.0.0 < 4.2.13"],"published":"2026-09-26","updated":"2026-09-26","sourceUpdated":"2026-09-26T07:17:03.430","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-96531","references":[{"url":"https://wpscan.com/vulnerability/15ad5748-8c2b-4c60-9818-57790f7033c7/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-26T06:27:03.679Z","slug":"CVE-2026-96531","body":"## Overview\n\nThe Optimole  WordPress plugin before 4.2.13 does not escape unrecognized attributes of its video-player block before rendering them onto the block's wrapper element, allowing users with the Author role and above to store an event-handler attribute that executes scripts in the browser of any user, such as an administrator, who views the post.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}