PT-2026-41636 · WordPress · Autoptimize+2

Matthew Rollings

·

Published

2026-05-18

·

Updated

2026-05-18

·

CVE-2026-3220

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Autoptimize versions prior to 3.1.15 Clearfy Cache versions prior to 2.4.2 Speed Optimizer versions prior to 7.7.9
Description Unauthenticated Stored Cross-Site Scripting (XSS) is possible due to a predictable replacement hash used during the HTML minification process and the abuse of a regular expression. This allows an attacker to anticipate the placeholder format and inject arbitrary HTML attributes into the final HTML output.
Recommendations Update Autoptimize to version 3.1.15 or later. Update Clearfy Cache to version 2.4.2 or later. Update Speed Optimizer to version 7.7.9 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-3220

Affected Products

Autoptimize
Clearfy Cache
Speed Optimizer