Impact
The vulnerability allows an unauthenticated attacker to insert arbitrary JavaScript into the site via the REQUEST_URI path. The script is stored by the Autoptimize plugin and later executed when pages that have the Critical CSS feature enabled load. This Stored XSS can lead to defacement, cookie theft, or session hijacking for any user who visits the affected page.
Affected Systems
All WordPress installations using the Autoptimize plugin version 3.1.15.1 or earlier are affected. The issue exists in every release up to and including 3.1.15.1, provided the Critical CSS feature is enabled and a valid API key is configured.
Risk and Exploitability
The CVSS score of 7.2 indicates a high‑risk compromise. The EPSS score is not available but the flaw is exploitable without authentication and relies on a consistent request path, making the attack straightforward. The vulnerability is not listed in the CISA KEV catalog, yet it remains a high‑impact exposure due to its wide reach across WordPress sites that have enabled Critical CSS.
OpenCVE Enrichment