---
id: CVE-2026-84829
title: >-
  The Optimole  WordPress plugin before 4.2.12 does not properly escape a user
  supplied value before using it to build an image tag attribute, allowing
  unauthenticated users to inject arbitrary attributes into pages served to
  every visitor…
summary: >-
  The Optimole  WordPress plugin before 4.2.12 does not properly escape a user
  supplied value before using it to build an image tag attribute, allowing
  unauthenticated users to inject arbitrary attributes into pages served to
  every visitor…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-79
product: Optimole
affected:
  - Optimole >= 4.2.3 < 4.2.12
published: '2026-09-16'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T13:16:49.843'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-84829'
references:
  - url: 'https://wpscan.com/vulnerability/c8489eb1-e767-4b19-a7c0-124eab843d9e/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-17T12:19:53.972863Z'
epss: 0.00505
epssPercentile: 0.40585
ingestedAt: '2026-09-16T06:51:06.249Z'
---

## Overview

The Optimole  WordPress plugin before 4.2.12 does not properly escape a user supplied value before using it to build an image tag attribute, allowing unauthenticated users to inject arbitrary attributes into pages served to every visitor, which leads to Stored Cross-Site Scripting.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
