The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer WordPress plugin before 7.7.9 are vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. This allows an attacker to inject arbitrary HTML attributes in the final HTML output by anticipating the placeholder format.
Metrics
Affected Vendors & Products
References
History
Mon, 18 May 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer WordPress plugin before 7.7.9 are vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. This allows an attacker to inject arbitrary HTML attributes in the final HTML output by anticipating the placeholder format. | |
| Title | Multiple Plugins - Unauthenticated Stored XSS via Minify Library | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-05-18T06:00:08.130Z
Reserved: 2026-02-25T18:04:15.464Z
Link: CVE-2026-3220
No data.
Status : Received
Published: 2026-05-18T07:16:12.270
Modified: 2026-05-18T07:16:12.270
Link: CVE-2026-3220
No data.
OpenCVE Enrichment
No data.