CVE-2026-5217Disclosure

LOWCVSS 7.2 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.2.2. This is due to insufficient input sanitization and output escaping on the user-supplied 's' parameter (srcset descriptor) in the unauthenticated /wp-json/optimole/v1/optimizations REST endpoint. The endpoint validates requests using an HMAC signature and timestamp, but these values are exposed directly in the frontend HTML making them accessible to any visitor. The plugin uses sanitize_text_field() on the descriptor value of rest.php, which strips HTML tags but does not escape double quotes. The poisoned descriptor is then stored via transients (backed by the WordPress options table) and later retrieved and injected verbatim into the srcset attribute of tag_replacer.php without proper escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts into pages that will execute whenever a user accesses the injected page.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-11); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-11: 2Mentions · 2026-04-18: 1PoC Mentioned / Linked · 2026-04-18: 1Technical Details · 2026-04-11: 204-1104-18
Signal classification3 categories
Disclosure
133.3%
General
133.3%
PoC
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-112
Disclosure1General1
2026-04-181
PoC1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-5217 The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all ver… https://www.cve.org/CVERecord?id=CVE-2026-5217

    Post summary

    The post announces CVE-2026-5217, identifying it as a stored XSS flaw in the Optimole WordPress plugin, with no additional exploitation or mitigation details provided.

    00010166
    57.1K followersView on X
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-5217-optimole-wp-version-4-2-2-high-vulnerability-proof-of-concept CVE-2026-5217 #WordPress plugin #vulnerability optimole-wp #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    The post shares a proof‑of‑concept for CVE‑2026‑5217 in the Optimole WP plugin but does not detail exploitation tools, active attacks, or mitigation steps.

    0000047
    6 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-5217 Stored Cross-Site Scripting in Optimole Image Optimization Plugin ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5217 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet announces CVE‑2026‑5217, identifying it as a stored XSS vulnerability in the Optimole plugin, and links to a Vulmon detail page without providing PoC, exploit tools, active exploitation reports, or patch information.

    0000041
    4.0K followersView on X

Explore more