Impact
Autoptimize, a popular WordPress cache and optimization plugin, contains a stored cross‑site scripting vulnerability tied to the comment author name field. When insufficient sanitization and escaping are applied to user input, an attacker can inject arbitrary JavaScript that is saved in the database and executed on every page load. The flaw is classified as CWE‑79, indicating insecure input handling that leads to XSS.
Affected Systems
Affected installations are all WordPress sites running Autoptimize versions up to and including 3.1.15.1, regardless of the site's overall version or theme. The vulnerability can be present in any environment where the plugin is installed and activated, even if the user does not have administrator privileges, because the stored payload requires only that a comment author’s name be accepted and later displayed.
Risk and Exploitability
The CVSS base score of 5.4 places this issue in the medium severity range. Exploitation is not trivial; the attacker must have the plugin’s ‘Lazy‑load images?’ option enabled, have the w3‑total‑cache plugin file present on disk while disabled, and trigger a plugin that loads the Minify_HTML class. Additionally, the attacker’s posted comment must be approved by a moderator before the payload is rendered. These prerequisites reduce the attack window, but once satisfied, an attacker can execute arbitrary scripts, potentially hijacking user sessions or stealing credentials. The vulnerability is not listed in CISA’s KEV catalog, and no EPSS value is available, though the existence of the conditions suggests that active exploitation is unlikely but still conceivable.
OpenCVE Enrichment