The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer WordPress plugin before 7.7.9 are vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. This allows an attacker to inject arbitrary HTML attributes in the final HTML output by anticipating the placeholder format.

Project Subscriptions

Vendors Products
Autoptimize Subscribe
Autoptimize Subscribe
Clearfy Cache Subscribe
Clearfy Cache Subscribe
Speed Optimizer Subscribe
Speed Optimizer Subscribe
Wordpress Subscribe
Wordpress Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 18 May 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 18 May 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Autoptimize
Autoptimize autoptimize
Clearfy Cache
Clearfy Cache clearfy Cache
Speed Optimizer
Speed Optimizer speed Optimizer
Wordpress
Wordpress wordpress
Vendors & Products Autoptimize
Autoptimize autoptimize
Clearfy Cache
Clearfy Cache clearfy Cache
Speed Optimizer
Speed Optimizer speed Optimizer
Wordpress
Wordpress wordpress

Mon, 18 May 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Mon, 18 May 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer WordPress plugin before 7.7.9 are vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. This allows an attacker to inject arbitrary HTML attributes in the final HTML output by anticipating the placeholder format.
Title Multiple Plugins - Unauthenticated Stored XSS via Minify Library
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-05-18T13:40:11.175Z

Reserved: 2026-02-25T18:04:15.464Z

Link: CVE-2026-3220

cve-icon Vulnrichment

Updated: 2026-05-18T13:40:08.400Z

cve-icon NVD

Status : Deferred

Published: 2026-05-18T07:16:12.270

Modified: 2026-05-18T17:05:46.240

Link: CVE-2026-3220

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-18T16:00:15Z

Weaknesses