Description
The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 3.1.15.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires an administrator to have enabled Autoptimize's 'Lazy-load images?' option, the w3-total-cache/w3-total-cache.php file to be present on disk with the plugin disabled, a class named Minify_HTML to be loaded into scope by another plugin, and the malicious comment to be approved by a moderator before the payload renders.
Published: 2026-10-02
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting via comment author name
Action: Apply Patch
AI Analysis

Impact

Autoptimize, a popular WordPress cache and optimization plugin, contains a stored cross‑site scripting vulnerability tied to the comment author name field. When insufficient sanitization and escaping are applied to user input, an attacker can inject arbitrary JavaScript that is saved in the database and executed on every page load. The flaw is classified as CWE‑79, indicating insecure input handling that leads to XSS.

Affected Systems

Affected installations are all WordPress sites running Autoptimize versions up to and including 3.1.15.1, regardless of the site's overall version or theme. The vulnerability can be present in any environment where the plugin is installed and activated, even if the user does not have administrator privileges, because the stored payload requires only that a comment author’s name be accepted and later displayed.

Risk and Exploitability

The CVSS base score of 5.4 places this issue in the medium severity range. Exploitation is not trivial; the attacker must have the plugin’s ‘Lazy‑load images?’ option enabled, have the w3‑total‑cache plugin file present on disk while disabled, and trigger a plugin that loads the Minify_HTML class. Additionally, the attacker’s posted comment must be approved by a moderator before the payload is rendered. These prerequisites reduce the attack window, but once satisfied, an attacker can execute arbitrary scripts, potentially hijacking user sessions or stealing credentials. The vulnerability is not listed in CISA’s KEV catalog, and no EPSS value is available, though the existence of the conditions suggests that active exploitation is unlikely but still conceivable.

Generated by OpenCVE AI on October 2, 2026 at 06:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Autoptimize to the latest release (3.1.16 or later) where the stored XSS issue is fixed.
  • If an update is not immediately possible, temporarily disable the 'Lazy‑load images?' option, as the flaw requires it to be enabled.
  • If the w3‑total‑cache plugin is present but disabled, remove or rename the w3‑total‑cache.php file from the server, or activate W3 Total Cache so that the file is no longer available to attackers.
  • Verify that any plugin loading the Minify_HTML class is disabled or removed until the fix is applied to eliminate the necessary class dependency.

Generated by OpenCVE AI on October 2, 2026 at 06:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
Description The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 3.1.15.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires an administrator to have enabled Autoptimize's 'Lazy-load images?' option, the w3-total-cache/w3-total-cache.php file to be present on disk with the plugin disabled, a class named Minify_HTML to be loaded into scope by another plugin, and the malicious comment to be approved by a moderator before the payload renders.
Title Autoptimize <= 3.1.15.1 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-02T05:30:18.257Z

Reserved: 2026-08-24T16:49:16.127Z

Link: CVE-2026-78471

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T06:16:41.240

Modified: 2026-10-02T13:18:55.613

Link: CVE-2026-78471

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T06:30:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')