
CVE-2026-2352 The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ao_post_preload' meta value in all versions up to, and including, 3.1.14. Thi… https://www.cve.org/CVERecord?id=CVE-2026-2352
Post summary
CVE-2026-2352 reveals a stored XSS flaw in the Autoptimize WordPress plugin up to version 3.1.14, but no PoC, exploit, exploitation reports, or patch information is included.
