Multiple Plugins <= Multiple Versions - Unauthenticated Stored Cross-Site Scripting
high
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- CVSS:
- 7.2
- Affected:
- up to 3.1.15
- Fixed in:
- 3.1.15
- Disclosed:
- Apr 27, 2026
CVE-2026-3220 on NVD →
Autoptimize <= 3.1.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Lazy-loaded Image Attributes
medium
The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the lazy-loading image processing in all versions up to, and including, 3.1.14. This is due to the use of an overly permissive regular expression in the `add_lazyload` function that replaces all occurrences of `\ssrc=` in image tags w...
- CVSS:
- 6.4
- Affected:
- up to 3.1.14
- Fixed in:
- 3.1.15
- Disclosed:
- Mar 20, 2026
CVE-2026-2430 on NVD →
Autoptimize <= 3.1.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'ao_post_preload' Meta Value
medium
The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ao_post_preload' meta value in all versions up to, and including, 3.1.14. This is due to insufficient input sanitization in the `ao_metabox_save()` function and missing output escaping when the value is rendered into a `<link>` t...
- CVSS:
- 6.4
- Affected:
- up to 3.1.14
- Fixed in:
- 3.1.15
- Disclosed:
- Mar 20, 2026
CVE-2026-2352 on NVD →
Autoptimize <= 3.1.13 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the LCP Image to preload metabox in all versions up to, and including, 3.1.13 due to insufficient input sanitization and output escaping on user-supplied image attributes in the "create_img_preload_tag" function. This makes it possibl...
- CVSS:
- 6.4
- Affected:
- up to 3.1.13
- Fixed in:
- 3.1.14
- Disclosed:
- Dec 3, 2025
CVE-2025-13401 on NVD →
Autoptimize [autoptimize] < 3.1.14
unknown
[en] The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the LCP Image to preload metabox in all versions up to, and including, 3.1.13 due to insufficient input sanitization and output escaping on user-supplied image attributes in the "create_img_preload_tag" function. This makes it po...
- Affected:
- up to 3.1.14
- Fixed in:
- 3.1.14
- Disclosed:
- Dec 3, 2025
CVE-2025-13401 on NVD →
Autoptimize [autoptimize] < 3.1.7 (closed)
unknown
[en] The Autoptimize WordPress plugin before 3.1.7 does not sanitise and escape the settings imported from a previous export, allowing high privileged users (such as an administrator) to inject arbitrary javascript into the admin panel, even when the unfiltered_html capability is disabled, such as in a multisite setup.
- Affected:
- up to 3.1.7
- Fixed in:
- 3.1.7
- Disclosed:
- May 30, 2023
CVE-2023-2113 on NVD →
Autoptimize <= 3.1.6 - Authenticated (Admin+) Stored Cross-Site Scripting via Critical CSS Rules
medium
The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the critical css rules in versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject a...
- CVSS:
- 4.4
- Affected:
- up to 3.1.6
- Fixed in:
- 3.1.7
- Disclosed:
- Apr 25, 2023
CVE-2023-2113 on NVD →
Autoptimize [autoptimize] < 3.1.7 (closed)
unknown
Update the WordPress Autoptimize plugin to the latest available version (at least 3.1.7).
An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Autoptimize Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other...
- Affected:
- up to 3.1.7
- Fixed in:
- 3.1.7
- Disclosed:
- Apr 25, 2023
Autoptimize [autoptimize] < 3.1.7 (closed)
unknown
Update the WordPress Autoptimize plugin to the latest available version (at least 3.1.7).
An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Autoptimize Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other...
- Affected:
- up to 3.1.7
- Fixed in:
- 3.1.7
- Disclosed:
- Apr 23, 2023
Autoptimize [autoptimize] < 3.1.0 (closed)
unknown
[en] The Autoptimize WordPress plugin before 3.1.0 uses an easily guessable path to store plugin's exported settings and logs.
- Affected:
- up to 3.1.0
- Fixed in:
- 3.1.0
- Disclosed:
- Jan 2, 2023
CVE-2022-4057 on NVD →
Autoptimize <= 3.0.4 - Sensitive Information Disclosure
medium
The Autoptimize plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.0.4 via the 'ao_ccss_export_callback' and 'ao_ccss_import_callback' functions. The settings.json file is not deleted in the import/export callbacks, which could lead to the settings options being lea...
- CVSS:
- 5.3
- Affected:
- up to 3.0.4
- Fixed in:
- 3.1.0
- Disclosed:
- Dec 5, 2022
CVE-2022-4057 on NVD →
Autoptimize [autoptimize] < 3.1.1 (closed)
unknown
[en] The Autoptimize WordPress plugin before 3.1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 3.1.1
- Fixed in:
- 3.1.1
- Disclosed:
- Sep 16, 2022
CVE-2022-2635 on NVD →
Autoptimize <= 3.1.0 - Authenticated (Admin+) Stored Cross-Site Scripting via Critical CSS Settings
medium
The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the critical css settings rules in versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to...
- CVSS:
- 5.5
- Affected:
- up to 3.1.0
- Fixed in:
- 3.1.1
- Disclosed:
- Jul 19, 2022
CVE-2022-2635 on NVD →
Autoptimize [autoptimize] < 2.7.8 (closed)
unknown
[en] The Autoptimize WordPress plugin before 2.7.8 does not check for malicious files such as .html in the archive uploaded via the 'Import Settings' feature. As a result, it is possible for a high privilege user to upload a malicious file containing JavaScript code inside an archive which will execute when a victim vi...
- Affected:
- up to 2.7.8
- Fixed in:
- 2.7.8
- Disclosed:
- Jun 21, 2021
CVE-2021-24378 on NVD →
Autoptimize [autoptimize] < 2.7.8 (closed)
unknown
[en] The Autoptimize WordPress plugin before 2.7.8 attempts to delete malicious files (such as .php) form the uploaded archive via the "Import Settings" feature, after its extraction. However, the extracted folders are not checked and it is possible to upload a zip which contained a directory with PHP file in it and th...
- Affected:
- up to 2.7.8
- Fixed in:
- 2.7.8
- Disclosed:
- Jun 21, 2021
CVE-2021-24376 on NVD →
Autoptimize [autoptimize] < 2.7.8 (closed)
unknown
[en] The Autoptimize WordPress plugin before 2.7.8 attempts to remove potential malicious files from the extracted archive uploaded via the 'Import Settings' feature, however this is not sufficient to protect against RCE as a race condition can be achieved in between the moment the file is extracted on the disk but not...
- Affected:
- up to 2.7.8
- Fixed in:
- 2.7.8
- Disclosed:
- Jun 21, 2021
CVE-2021-24377 on NVD →
Autoptimize [autoptimize] < 2.8.4 (closed)
unknown
[en] The Autoptimize WordPress plugin before 2.8.4 was missing proper escaping and sanitisation in some of its settings, allowing high privilege users to set XSS payloads in them, leading to stored Cross-Site Scripting issues
- Affected:
- up to 2.8.4
- Fixed in:
- 2.8.4
- Disclosed:
- May 24, 2021
CVE-2021-24332 on NVD →
Autoptimize <= 2.8.3 - Stored Cross-Site Scripting
medium
The Autoptimize WordPress plugin before 2.8.4 was missing proper escaping and sanitisation in some of its settings, allowing high privilege users to set XSS payloads in them, leading to stored Cross-Site Scripting issues.
- CVSS:
- 5.5
- Affected:
- up to 2.8.4
- Fixed in:
- 2.8.4
- Disclosed:
- May 7, 2021
CVE-2021-24332 on NVD →
Autoptimize [autoptimize] < 2.8.4 (closed)
unknown
Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by m0ze in WordPress Autoptimize plugin (versions <= 2.8.3).
- Affected:
- up to 2.8.4
- Fixed in:
- 2.8.4
- Disclosed:
- May 4, 2021
Autoptimize <= 2.7.7 - Arbitrary File Upload (and Remote Code Execution) via Import Settings
critical
The Autoptimize WordPress plugin before 2.7.8 attempts to delete malicious files (such as .php) form the uploaded archive via the "Import Settings" feature, after its extraction. However, the extracted folders are not checked and it is possible to upload a zip which contained a directory with PHP file in it and then it...
- CVSS:
- 9.8
- Affected:
- up to 2.7.8
- Fixed in:
- 2.7.8
- Disclosed:
- Oct 9, 2020
CVE-2021-24376 on NVD →
Autoptimize <= 2.7.7 - Race Condition leading to Remote Code Execution
high
The Autoptimize WordPress plugin before 2.7.8 attempts to remove potential malicious files from the extracted archive uploaded via the 'Import Settings' feature, however this is not sufficient to protect against RCE as a race condition can be achieved in between the moment the file is extracted on the disk but not yet...
- CVSS:
- 8.1
- Affected:
- up to 2.7.8
- Fixed in:
- 2.7.8
- Disclosed:
- Oct 9, 2020
CVE-2021-24377 on NVD →
Autoptimize <= 2.7.7 - Unsafe File Upload to Cross-Site Scripting
medium
The Autoptimize WordPress plugin before 2.7.8 does not check for malicious files such as .html in the archive uploaded via the 'Import Settings' feature. As a result, it is possible for a high privilege user to upload a malicious file containing JavaScript code inside an archive which will execute when a victim visits...
- CVSS:
- 4.8
- Affected:
- up to 2.7.8
- Fixed in:
- 2.7.8
- Disclosed:
- Oct 9, 2020
CVE-2021-24378 on NVD →
Autoptimize [autoptimize] < 2.7.7 (closed)
unknown
[en] The ao_ccss_import AJAX call in Autoptimize Wordpress Plugin 2.7.6 does not ensure that the file provided is a legitimate Zip file, allowing high privilege users to upload arbitrary files, such as PHP, leading to remote command execution.
- Affected:
- up to 2.7.7
- Fixed in:
- 2.7.7
- Disclosed:
- Sep 3, 2020
CVE-2020-24948 on NVD →
Autoptimize <= 2.7.6 - Authenticated Arbitrary File Upload
high
The ao_ccss_import AJAX call in Autoptimize Wordpress Plugin 2.7.6 does not ensure that the file provided is a legitimate Zip file, allowing high privilege users to upload arbitrary files, such as PHP, leading to remote command execution.
- CVSS:
- 7.2
- Affected:
- up to 2.7.6
- Fixed in:
- 2.7.7
- Disclosed:
- Aug 24, 2020
CVE-2020-24948 on NVD →
Autoptimize <= 2.1.0 - Unauthenticated Local File Inclusion
critical
The Autoptimize plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.0. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensit...
- CVSS:
- 9.8
- Affected:
- up to 2.1.0
- Fixed in:
- 2.1.1
- Disclosed:
- Jun 19, 2017
Autoptimize [autoptimize] < 2.1.1 (closed)
unknown
The Autoptimize plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.0. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensit...
- Affected:
- up to 2.1.1
- Fixed in:
- 2.1.1
- Disclosed:
- Jun 19, 2017
Autoptimize [autoptimize] < 3.1.0 (closed)
unknown
Update the WordPress Autoptimize plugin to the latest available version (at least 3.1.0).
Raad Haddad (Cloudyrion GmbH) discovered and reported this Sensitive Data Exposure vulnerability in WordPress Autoptimize Plugin. This vulnerability has been fixed in version 3.1.0.
- Affected:
- up to 3.1.0
- Fixed in:
- 3.1.0
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database