Retour à la veille

CVE-2026-96530

Publié : 7 octobre 2026
Modifié : 7 octobre 2026
Lien officiel NVD

Description détaillée

The Optimole WordPress plugin before 4.2.15 does not perform a capability check before exposing its stored image-optimization account data in a dashboard widget, allowing any authenticated user, including Subscribers, to read the site's third-party service credentials.

Références et Patchs