The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer WordPress plugin before 7.7.9 are vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. This allows an attacker to inject arbitrary HTML attributes in the final HTML output by anticipating the placeholder format.
History

Mon, 18 May 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer WordPress plugin before 7.7.9 are vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. This allows an attacker to inject arbitrary HTML attributes in the final HTML output by anticipating the placeholder format.
Title Multiple Plugins - Unauthenticated Stored XSS via Minify Library
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-05-18T06:00:08.130Z

Reserved: 2026-02-25T18:04:15.464Z

Link: CVE-2026-3220

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-18T07:16:12.270

Modified: 2026-05-18T07:16:12.270

Link: CVE-2026-3220

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.