CVE-2026-14995

LOWCVSS 7.2 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI Path in all versions up to, and including, 3.1.15.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the Critical CSS feature to be active with a valid API key configured, as this is the precondition for unauthenticated frontend requests to trigger queue entries via ao_ccss_enqueue().

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-10-01: 210-01
Referenced assets2 URLs
Full discourse2 posts
  • 株式会社mgn@mgn_jpn

    🚨 Autoptimize に脆弱性(深刻度 高) 80万サイト以上が利用 / CVSS 7.2 修正版 3.1.16 が公開済み https://shindan.m-g-n.me/alerts/cve-2026-14995/

    00011406
    336 followersView on X
  • CVE@CVEnew

    CVE-2026-14995 The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI Path in all versions up to, and including, 3.1.15.1 due to insuffici… https://www.cve.org/CVERecord?id=CVE-2026-14995

    00000763
    58.1K followersView on X

Explore more