Sceawere

Vulnerability Detail

CVE-2026-96897UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Optima Express Unauthenticated Account Creation

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
1d ago
Vendor
Unknown
Product
Optima Express IDX
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Optima Express IDX WordPress plugin before 8.7.6 does not perform any authorisation check on one of its AJAX actions that is available to logged-out users, allowing unauthenticated attackers to force the creation of a fixed author-role account and to repeatedly rotate its application password on any connected install.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-09-27T06:17:22.927Z",
  "pubdate": "2026-09-27T06:17:22.927Z",
  "executiveSummary": "The Optima Express IDX WordPress plugin prior to version 8.7.6 contains a critical security vulnerability involving improper authorization for AJAX-based administrative actions.\nThe vulnerability allows unauthenticated, remote attackers to trigger account creation processes that should otherwise be restricted to authorized personnel.\nAn attacker can force the creation of an account with the 'author' role and subsequently cycle or rotate the application password associated with that account.\nThis flaw presents a severe risk as it grants an unauthenticated entity the ability to establish persistent, unauthorized access to the WordPress environment.\nThe vulnerability is accessible over the network to any remote, unauthenticated user, requiring no prior knowledge of credentials or existing sessions.\nSuccessful exploitation facilitates unauthorized account provisioning and potential account takeover, undermining the integrity of the WordPress user authentication system.",
  "technicalDetails": "The root cause of this vulnerability lies in an insecure AJAX endpoint implementation within the Optima Express IDX plugin. The affected function fails to verify the current user's session or authentication status, treating requests originating from unauthenticated, remote actors as valid administrative commands.\nIn a standard WordPress environment, administrative actions such as user account creation are restricted by capability checks (e.g., 'manage_options' or 'create_users'). The plugin's failure to enforce these checks on its publicly exposed AJAX action circumvents the WordPress security model.\nThe attack flow begins with the adversary crafting an HTTP request directed at the plugin's vulnerable AJAX endpoint. By mimicking the structure of the plugin's internal request format, the attacker initiates a process that forces the application to register a new user account with the 'author' role.\nFurthermore, the vulnerability permits the systematic rotation or modification of the application password for the account created. By repeatedly invoking the vulnerable function, the attacker can force password changes, effectively maintaining control and ensuring the account remains functional across connected installations or services.\nThe vulnerability affects all versions of the Optima Express IDX WordPress plugin prior to 8.7.6. Because the action is hooked into the WordPress AJAX handler, it is accessible via the standard admin-ajax.php interface, which is typically reachable by any visitor to the site, regardless of their authorization status.\nUpon exploitation, the impact is significant: the attacker gains a functional user account within the 'author' role. While the 'author' role has limited privileges compared to an administrator, it provides legitimate access to the dashboard, the ability to read private posts, and the capability to manage their own content. The ability to rotate the application password allows the attacker to maintain persistence even if standard password reset mechanisms are attempted, creating a significant security burden for administrators attempting to remediate the unauthorized account access."
}
CVE-2026-96897: Optima Express Unauthenticated Account Creation (MEDIUM Severity, CVSS: 5.3) | Sceawere