Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Alto CVE-2026-93901 Multiple Vendors

Escalación de privilegios alta en plugin Optima Express IDX para WordPress hasta v8.7.5

Vulnerabilidad · Publicado 25/09/2026

7.3
CVSS 3.x
04 Medio7 Alto9 Crítico10
Severidad: Alto
Resumen ejecutivo

El plugin Optima Express IDX para WordPress contiene una vulnerabilidad de escalación de privilegios (CVSS 7.3) que permite a atacantes no autenticados ejecutar funciones administrativas a través de la acción AJAX `wp_ajax_nopriv_ihf_clear_cache`. La vulnerabilidad afecta todas las versiones hasta la 8.7.5 y expone sitios inmobiliarios y portales empresariales en México y LATAM que utilizan este plugin. Un atacante podría comprometer credenciales de autenticación y obtener acceso administrativo completo.

Análisis asistido por IA, contexto LATAM revisado por el equipo 2MCI.

Descripción técnica

Descripción técnica

The Optima Express IDX plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 8.7.5. This is due to the `provisionBlogCredentials()` function in `iHomefinderAdmin.php` being reachable via the `wp_ajax_nopriv_ihf_clear_cache` AJAX action — through the call chain `iHomefinderAjaxHandler::clearCache()` → `activateAuthenticationToken()` → `getAuthenticationInfo()` → `provisionBlogCredentials()` — with no capability check, nonce verification, or ownership validation, and the function unconditionally calling `$user->set_role('author')` on whichever WordPress account matches the hard-coded login `optima-express` via `get_user_by('login', 'optima-express')`. This makes it possible for unauthenticated attackers to escalate a pre-registered `optima-express` account to the Author role, gaining `publish_posts`, `upload_files`, and `edit_published_posts` capabilities, including access to the plugin's own `/wp-json/optima-express/v1/blog-post` REST endpoint. Exploitation requires open user registration to be enabled on the target site, and the attacker must register the `optima-express` username before the plugin has had the opportunity to provision that login for its own integration account.

Puntuación CVSS

Score: 7.3/10 — Severidad: HIGH — Estado NIST: Received

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Debilidades (CWE)

CWE-269

Fuente oficial

Publicado en NIST NVD.

¿Qué hacer?
  • Actualizar Optima Express IDX a versión posterior a 8.7.5 inmediatamente
  • Si no hay parche disponible, desactivar y eliminar el plugin
  • Revisar logs de acceso AJAX en `wp-admin/admin-ajax.php` buscando llamadas a `ihf_clear_cache` de direcciones IP sospechosas
  • Auditar permisos de usuarios y roles administrativos
  • Implementar protección de AJAX con validación de nonce en todos los endpoints
Esta alerta fue generada automáticamente a partir del NVD del NIST.