Sceawere
Vulnerability Detail
CVE-2026-78471UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Autoptimize Stored Cross-Site Scripting
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.4
- Creation Date
- 17h ago
- Vendor
- optimizingmatters
- Product
- Autoptimize
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 3.1.15.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires an administrator to have enabled Autoptimize's 'Lazy-load images?' option, the w3-total-cache/w3-total-cache.php file to be present on disk with the plugin disabled, a class named Minify_HTML to be loaded into scope by another plugin, and the malicious comment to be approved by a moderator before the payload renders.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.4",
"pubDate": "2026-10-02T06:16:41.240Z",
"pubdate": "2026-10-02T06:16:41.240Z",
"executiveSummary": "The Autoptimize plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability in versions up to and including 3.1.15.1. The flaw originates from inadequate input sanitization and output escaping of the comment author name field.\nThis vulnerability allows an unauthenticated attacker to inject malicious JavaScript payloads into comment sections. When a user—typically an administrator—views an injected page, the script executes within the context of their session, potentially leading to unauthorized actions or session hijacking.\nThe vulnerability is highly contextual, requiring specific environment configurations for successful exploitation. Attackers must have their malicious comments approved by a moderator. Exploitation prerequisites include the activation of the 'Lazy-load images?' option within Autoptimize, the presence of the 'w3-total-cache/w3-total-cache.php' file on the filesystem with the plugin disabled, and the global loading of the 'Minify_HTML' class by a third-party plugin.\nThe risk is significant due to the nature of Stored XSS, which persists on the server and executes automatically upon page load, granting attackers the ability to manipulate the browser environment of authenticated users.",
"technicalDetails": "The root cause of this vulnerability is the failure of the Autoptimize plugin to perform robust input validation or output escaping on the comment author name. This enables the injection of arbitrary HTML and JavaScript into the DOM during the comment rendering process.\nThe exploitation flow begins when an unauthenticated attacker submits a comment containing a malicious script payload in the author name field. For the payload to render, the comment must first pass through the WordPress moderation process and be approved by an administrator.\nSuccessful execution is contingent upon a specific environmental state. The 'Lazy-load images?' feature in Autoptimize must be enabled. Furthermore, the system must detect the presence of the 'w3-total-cache/w3-total-cache.php' file on the disk (even if the plugin is inactive), and a third-party plugin must provide the 'Minify_HTML' class into the global namespace.\nWhen these conditions are met, the plugin incorrectly processes the stored comment author name. When a victim loads the page containing the malicious comment, the injected script is executed by the browser. Because the script runs in the context of the victim's authenticated session, the impact includes unauthorized execution of administrative actions, data exfiltration via API calls, or the redirection of users to malicious external domains.\nThe vulnerability highlights a failure in the plugin's data handling logic, specifically within the module responsible for processing and optimizing front-end content. By failing to sanitize the author name string, Autoptimize inadvertently facilitates a bridge between user-submitted data and the DOM. This represents a classic Stored XSS vector, where the malicious content is stored persistently in the database and distributed to every user who visits the affected page. The requirement for specific helper classes and file system states suggests a conflict or improper interaction between the plugin's optimization logic and external legacy code fragments, which essentially inadvertently re-enables or utilizes vulnerable code paths for script rendering."
}