HarborGuard / CVE
Back to search
HIGHCVE-2026-3220Published Modified CNA WPScan

CVE-2026-3220: Multiple Plugins - Unauthenticated Stored XSS via Minify Library

The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer WordPress plugin before 7.7.9 are vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. This allows an attacker to inject arbitrary HTML attributes in the final HTML output by anticipating the placeholder format.

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
2.4.2
Affected Products
3

Fix available

2.4.23.1.157.7.9
Affected packages
  • Unknown / Autoptimize
    < 3.1.15 (from 0)
  • Unknown / Clearfy Cache
    < 2.4.2 (from 0)
  • Unknown / Speed Optimizer
    < 7.7.9 (from 0)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
References