Unauthenticated Stored XSS Vulnerability in Autoptimize and Other WordPress Plugins
CVE-2026-3220
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 May 2026
Badges
What is CVE-2026-3220?
The Autoptimize and other related WordPress plugins are susceptible to unauthenticated stored cross-site scripting (XSS) due to a flaw in the HTML minification process. This vulnerability originates from a predictable replacement hash, which attackers can exploit by injecting malicious HTML attributes into the final output. The misuse of a regular expression in the minification logic enables attackers to manipulate the output, posing significant security risks. Updating to the latest versions is imperative to mitigate this threat.
Affected Version(s)
Autoptimize 0 < 3.1.15
Clearfy Cache 0 < 2.4.2
Speed Optimizer 0 < 7.7.9
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.