Junglewise Threat Intelligence

CVE-2026-84829: Optimole Stored Cross-Site Scripting in image tag attributes

CVE-2026-84829 · Severity: high · CVSS 8.8 · Published 2026-09-16

Technologies: Optimole. Vendors: Optimole.

Executive brief

Optimole is a popular WordPress plugin that optimizes images for faster website loading. An improper escaping vulnerability in versions before 4.2.12 allows unauthenticated attackers to inject malicious code into image attributes, which is then stored and served to all site visitors. This can lead to credential theft, malware distribution, or defacement of the website.

Technical details

The vulnerability is a Stored Cross-Site Scripting (XSS) flaw (CWE-79) in the Optimole WordPress plugin. The plugin fails to properly escape user-supplied values before using them in image tag attributes, specifically in the srcset descriptor parameter. Unauthenticated attackers can inject arbitrary HTML/JavaScript attributes through this parameter. Previous escaping added in version 4.2.3 did not account for the final context in which the value is used, so versions 4.2.3 through 4.2.11 remain vulnerable. The injected payload is stored in the database and rendered to all site visitors, making this a high-impact stored XSS. A patch is available in version 4.2.12.

Affected products

  • Optimole Optimole before 4.2.12

Timeline

  • 2026-09-14: disclosed
  • 2026-09-16: patched: Fixed in version 4.2.12

References

Related threats