Sceawere

Vulnerability Detail

CVE-2026-96899UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Optima Express IDX Stored XSS

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.8
Creation Date
1d ago
Vendor
Unknown
Product
Optima Express IDX
Attack Type
CWE-79 Cross-Site Scripting (XSS)
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The Optima Express IDX WordPress plugin before 8.7.6 does not properly neutralise a script value submitted through one of its REST endpoints before storing it and echoing it into the document head when the post is rendered, allowing users with a role as low as author to perform Stored Cross-Site Scripting attacks.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.8",
  "pubDate": "2026-09-27T06:17:23.037Z",
  "pubdate": "2026-09-27T06:17:23.037Z",
  "executiveSummary": "The Optima Express IDX WordPress plugin before version 8.7.6 contains a stored Cross-Site Scripting (XSS) vulnerability. The flaw originates from improper input neutralization within a REST API endpoint, allowing malicious script injection.\nThe vulnerability enables users with an 'author' role or higher to inject arbitrary JavaScript into the application, which is subsequently rendered in the document head when the affected post is viewed.\nSuccessful exploitation results in the execution of attacker-supplied scripts within the context of the victim's browser session. This can lead to unauthorized actions, session hijacking, credential theft, or the modification of site content.\nBecause the vulnerability is stored, the impact persists across sessions and affects any user who views the compromised post, posing a significant risk to site integrity and administrative security.\nRemediation requires updating the plugin to version 8.7.6 or later, which includes necessary sanitization controls to neutralize input before storage.",
  "technicalDetails": "The vulnerability exists due to a lack of server-side input sanitization for specific parameters accepted by a REST API endpoint within the Optima Express IDX plugin. The application logic fails to apply adequate input validation or context-aware encoding to data submitted via this endpoint before it is persisted in the database.\nWhen a post or page associated with the plugin is rendered, the application retrieves this unsanitized data and injects it directly into the HTML document head. Because the input is echoed without escaping, the browser interprets the data as executable code rather than plain text.\nThe attack flow begins with an authenticated user, holding at least the 'author' role, interacting with the vulnerable REST endpoint. The attacker submits a crafted payload containing malicious JavaScript within the susceptible parameter. The server processes this request and stores the malicious string in the WordPress database associated with the post configuration.\nOnce the post is rendered, the plugin retrieves the malicious payload from the database and injects it into the site's document head. When any user—including administrators—views the rendered page, the browser executes the stored payload in the context of the user's active session.\nThe scope of this vulnerability is significant, as it bypasses standard security expectations for input handling. An attacker can leverage this for various post-exploitation activities, including but not limited to: stealing session cookies (Session Hijacking), performing administrative actions on behalf of the victim (Cross-Site Request Forgery), or redirecting users to malicious external domains.\nThe vulnerability is restricted to versions prior to 8.7.6. The requirement for 'author' level access means this is not an unauthenticated attack, but it poses a critical risk from compromised or malicious internal accounts. The root cause is categorized as an improper neutralization of input during web page generation (CWE-79), specifically resulting from insufficient input filtering on a REST API interface."
}
CVE-2026-96899: Optima Express IDX Stored XSS (MEDIUM Severity, CVSS: 6.8) | Sceawere