CVE 8.8 HIGH

Multiple Plugins – Unauthenticated Stored XSS via Minify Library_CVE-2026-3220

8.8 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Description

The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer WordPress plugin before 7.7.9 are vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. This allows an attacker to inject arbitrary HTML attributes in the final HTML output by anticipating the placeholder format.

AI Analysis

Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability in multiple WordPress plugins due to a predictable replacement hash used during the HTML minification process.

Basic Information

ID CVE-2026-3220
Source WPScan
Published May 18, 2026 at 06:00
Modified May 18, 2026 at 13:40

Affected Product

Vendor Unknown
Product Autoptimize
Affected Versions Unknown Autoptimize 0
Unknown Clearfy Cache 0
Unknown Speed Optimizer 0

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor Autoptimize, Clearfy, Speed Optimizer
Product Autoptimize, Clearfy Cache, Speed Optimizer
Version 3.1.15, 2.4.2, 7.7.9

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.