Vulnerability Description
The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer WordPress plugin before 7.7.9 are vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. This allows an attacker to inject arbitrary HTML attributes in the final HTML output by anticipating the placeholder format.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-3220?
CVE-2026-3220 is a vulnerability with a CVSS score of 8.8 (HIGH). The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer WordPress plugin before 7.7.9 are vulnerable to unauthenticated Stored Cross-Site Scripti...
How severe is CVE-2026-3220?
CVE-2026-3220 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-3220?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.