Extension WordPress
Vulnérabilités Autoptimize
Cette page rassemble les failles publiées pour Autoptimize, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Autoptimize
12 fiches
Autoptimize <= 3.1.14 – Authenticated (Contributor+) Stored Cross-Site Scripting via Lazy-loaded Image Attributes
The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the lazy-loading image processing in all versions up to, and including, 3.1.14. This is due to the use of an overly permissive regular expression in the…
*-3.1.14
3.1.15
20/03/2026
Autoptimize <= 3.1.14 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'ao_post_preload' Meta Value
The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ao_post_preload' meta value in all versions up to, and including, 3.1.14. This is due to insufficient input sanitization in the `ao_metabox_save()` function and missing output…
*-3.1.14
3.1.15
20/03/2026
Autoptimize <= 3.1.13 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the LCP Image to preload metabox in all versions up to, and including, 3.1.13 due to insufficient input sanitization and output escaping on user-supplied image attributes…
*-3.1.13
3.1.14
03/12/2025
Autoptimize <= 3.1.6 – Authenticated (Admin+) Stored Cross-Site Scripting via Critical CSS Rules
The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the critical css rules in versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
*-3.1.6
3.1.7
25/04/2023
Autoptimize <= 3.0.4 – Sensitive Information Disclosure
The Autoptimize plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.0.4 via the 'ao_ccss_export_callback' and 'ao_ccss_import_callback' functions. The settings.json file is not deleted in the import/export callbacks, which could lead to…
*-3.0.4
3.1.0
05/12/2022
Autoptimize <= 3.1.0 – Authenticated (Admin+) Stored Cross-Site Scripting via Critical CSS Settings
The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the critical css settings rules in versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-3.1.0
3.1.1
19/07/2022
Autoptimize <= 2.8.3 – Stored Cross-Site Scripting
The Autoptimize WordPress plugin before 2.8.4 was missing proper escaping and sanitisation in some of its settings, allowing high privilege users to set XSS payloads in them, leading to stored Cross-Site Scripting issues.
[*, 2.8.4)
2.8.4
07/05/2021
Autoptimize <= 2.7.7 – Race Condition leading to Remote Code Execution
The Autoptimize WordPress plugin before 2.7.8 attempts to remove potential malicious files from the extracted archive uploaded via the 'Import Settings' feature, however this is not sufficient to protect against RCE as a race condition can be achieved…
[*, 2.7.8)
2.7.8
09/10/2020
Autoptimize <= 2.7.7 – Unsafe File Upload to Cross-Site Scripting
The Autoptimize WordPress plugin before 2.7.8 does not check for malicious files such as .html in the archive uploaded via the 'Import Settings' feature. As a result, it is possible for a high privilege user to upload a…
[*, 2.7.8)
2.7.8
09/10/2020
Autoptimize <= 2.7.7 – Arbitrary File Upload (and Remote Code Execution) via Import Settings
The Autoptimize WordPress plugin before 2.7.8 attempts to delete malicious files (such as .php) form the uploaded archive via the "Import Settings" feature, after its extraction. However, the extracted folders are not checked and it is possible to…
[*, 2.7.8)
2.7.8
09/10/2020
Autoptimize <= 2.7.6 – Authenticated Arbitrary File Upload
The ao_ccss_import AJAX call in Autoptimize Wordpress Plugin 2.7.6 does not ensure that the file provided is a legitimate Zip file, allowing high privilege users to upload arbitrary files, such as PHP, leading to remote command execution.
*-2.7.6
2.7.7
24/08/2020
Autoptimize <= 2.1.0 – Unauthenticated Local File Inclusion
The Autoptimize plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.0. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code…
*-2.1.0
2.1.1
19/06/2017
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.