plugin

Optimole Wp Vulnerabilities

9 known security issues reported for the Optimole Wp WordPress plugin. Most recent disclosed Aug 27, 2026.

3 high 6 medium

Running Optimole Wp on your site? Check whether your installed version is affected.

Scan your site free

Optimole <= 4.2.10 - Unauthenticated Stored Cross-Site Scripting via 'a' (above_fold_images) Parameter

high

The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'a' (above_fold_images) parameter in all versions up to, and including, 4.2.10 due to insufficient input sanitization and output escaping. This makes it p...

CVSS:
7.2
Affected:
up to 4.2.10
Fixed in:
4.2.11
Disclosed:
Aug 27, 2026

CVE-2026-77365 on NVD →

Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization <= 4.2.7 - Unauthenticated Stored Cross-Site Scripting

high

The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.2.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject...

CVSS:
7.2
Affected:
up to 4.2.7
Fixed in:
4.2.8
Disclosed:
Jun 30, 2026

CVE-2026-57673 on NVD →

Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization <= 4.2.6 - Cross-Site Request Forgery via 'optml_replace_file' AJAX Action

medium

The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.6. This is due to missing or incorrect nonce validation on the replace_file function. This makes it possible for unauthen...

CVSS:
4.3
Affected:
up to 4.2.6
Fixed in:
4.2.7
Disclosed:
Jun 17, 2026

CVE-2026-11784 on NVD →

Optimole <= 4.2.2 - Unauthenticated Stored Cross-Site Scripting via Srcset Descriptor Parameter

high

The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.2.2. This is due to insufficient input sanitization and output escaping on the user-supplied 's' parameter (srcset descrip...

CVSS:
7.2
Affected:
up to 4.2.2
Fixed in:
4.2.3
Disclosed:
Apr 10, 2026

CVE-2026-5217 on NVD →

Optimole <= 4.2.3 - Reflected Cross-Site Scripting via Page Profiler URL

medium

The Optimole – Optimize Images in Real Time plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL paths in versions up to, and including, 4.2.3 This is due to insufficient output escaping on user-supplied URL paths in the get_current_url() function, which are inserted into JavaScript code via str...

CVSS:
6.1
Affected:
up to 4.2.3
Fixed in:
4.2.4
Disclosed:
Apr 10, 2026

CVE-2026-5226 on NVD →

Image optimization service by Optimole <= 4.1.0 - Insecure Direct Object Reference to Authenticated (Author+) Media Offload

medium

The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.0 via the /wp-json/optml/v1/move_image REST API endpoint due to missing validation on a user controlled key. This m...

CVSS:
4.3
Affected:
up to 4.1.0
Fixed in:
4.1.1
Disclosed:
Oct 17, 2025

CVE-2025-11519 on NVD →

Image Optimization by Optimole – Lazy Load, CDN, Convert WebP & AVIF <= 3.12.10 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload

medium

The Image Optimization by Optimole – Lazy Load, CDN, Convert WebP & AVIF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘allow_meme_types’ function in versions up to, and including, 3.12.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated at...

CVSS:
6.4
Affected:
up to 3.12.10
Fixed in:
3.13.0
Disclosed:
May 14, 2024

CVE-2024-4636 on NVD →

ThemeIsle SDK <= Various Versions - Missing Authorization

medium

Multiple plugins and/or themes for WordPress with the ThemeIsle SDK are vulnerable to unauthorized modification of data due to a missing capability check on the register_reference() function in various versions. This makes it possible for unauthenticated attackers to update options values that allow ThemeIsle to track...

CVSS:
5.3
Affected:
up to 3.12.4
Fixed in:
3.12.5
Disclosed:
Feb 1, 2024

CVE-2024-1047 on NVD →

Image optimization & Lazy Load <= 3.3.1 - Admin+ Stored Cross-Site Scripting

medium

The Image optimization & Lazy Load by Optimole WordPress plugin before 3.3.2 does not sanitise and escape its "Lazyload background images for selectors" settings, which could allow high privilege users such as admin to perform Cross-Site scripting attacks even when the unfiltered_html capability is disallowed.

CVSS:
4.8
Affected:
up to 3.3.2
Fixed in:
3.3.2
Disclosed:
Mar 21, 2022

CVE-2022-0969 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database