The Optima Express IDX WordPress plugin before 8.7.6 does not perform any authorisation check on one of its AJAX actions that is available to logged-out users, allowing unauthenticated attackers to force the creation of a fixed author-role account and to repeatedly rotate its application password on any connected install.
PUBLISHED5.2
Optima Express 8.5.0 - 8.7.5 - Unauthenticated Author Account Creation & Application Password Rotation via ihf_clear_cache
Problem type
- CWE-862 Missing Authorization
Affected products
Unknown
Optima Express IDX
< 8.7.6 - AFFECTED
References
GitHub Security Advisories
GHSA-fx75-253r-968v
The Optima Express IDX WordPress plugin before 8.7.6 does not perform any authorisation check on...
https://github.com/advisories/GHSA-fx75-253r-968vThe Optima Express IDX WordPress plugin before 8.7.6 does not perform any authorisation check on one of its AJAX actions that is available to logged-out users, allowing unauthenticated attackers to force the creation of a fixed author-role account and to repeatedly rotate its application password on any connected install.
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-96897Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-96897",
"assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"assignerShortName": "WPScan",
"dateUpdated": "2026-09-27T06:00:22.476Z",
"dateReserved": "2026-09-23T19:54:38.933Z",
"datePublished": "2026-09-27T06:00:22.476Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"shortName": "WPScan",
"dateUpdated": "2026-09-27T06:00:22.476Z"
},
"title": "Optima Express 8.5.0 - 8.7.5 - Unauthenticated Author Account Creation & Application Password Rotation via ihf_clear_cache",
"descriptions": [
{
"lang": "en",
"value": "The Optima Express IDX WordPress plugin before 8.7.6 does not perform any authorisation check on one of its AJAX actions that is available to logged-out users, allowing unauthenticated attackers to force the creation of a fixed author-role account and to repeatedly rotate its application password on any connected install."
}
],
"affected": [
{
"vendor": "Unknown",
"product": "Optima Express IDX",
"defaultStatus": "unaffected",
"versions": [
{
"version": "8.5.0",
"status": "affected",
"versionType": "semver",
"lessThan": "8.7.6"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "CWE-862 Missing Authorization",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://wpscan.com/vulnerability/f9fd04f4-282d-486f-8561-dbf02250282a/",
"tags": [
"exploit",
"vdb-entry",
"technical-description"
]
}
],
"credits": [
{
"lang": "en",
"value": "Alex Spataru",
"type": "finder"
},
{
"lang": "en",
"value": "WPScan",
"type": "coordinator"
}
]
}
}
}