CVE-2026-2430Active Exploitation

MEDIUMCVSS 6.4 · MEDIUM

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the lazy-loading image processing in all versions up to, and including, 3.1.14. This is due to the use of an overly permissive regular expression in the `add_lazyload` function that replaces all occurrences of `\ssrc=` in image tags without limiting to the actual attribute. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page by crafting an image tag where the `src` URL contains a space followed by `src=`, causing the regex to break the HTML structure and promote text inside attribute values into executable HTML attributes.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-08-20)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-21: 1Mentions · 2026-08-20: 2Active Exploitation · 2026-08-20: 2Patch / Workaround · 2026-08-20: 1Technical Details · 2026-03-21: 1Technical Details · 2026-08-20: 203-2108-20
Signal classification2 categories
Active Exploitation
266.7%
Disclosure
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-03-211
Disclosure1
2026-08-202
Active Exploitation2
Full discourse3 posts
  • Carlos Fynn@fynn_JourX
    Active Exploitation

    Microsoft Copilot CoSnitch Data Exposure (CVE-2026-2430… is the kind of management-plane bug defenders should move on fast. It combines active exploitation with security exposure and auth bypass risk in FortiClient EMS. When endpoint management infrastructure is expose…

    Post summary

    The post indicates that CVE-2026-2430 is actively exploited, exposing management‑plane data in FortiClient EMS and enabling authentication bypass, but it offers no PoC, exploit code, or patch information.

    0000064
    85 followersView on X
  • Lucas@lucasverdan
    Active Exploitation

    Microsoft Copilot CoSnitch Data Exposure (CVE-2026-2430… is already being exploited, and Fortinet says the FortiClient EMS flaw carries security exposure and auth bypass risk. If you run 7.4.5 or 7.4.6, treat it as exposed management-plane risk and hotfix now.

    Post summary

    CVE‑2026‑2430 is reported to be actively exploited, with Fortinet flagging an auth bypass flaw in FortiClient EMS. Users of versions 7.4.5 and 7.4.6 are urged to apply a hotfix immediately.

    0000075
    311 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2430 The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the lazy-loading image processing in all versions up to, and including, 3.1.14. Th… https://www.cve.org/CVERecord?id=CVE-2026-2430

    Post summary

    The Autoptimize WordPress plugin is disclosed to have a stored XSS vulnerability in its lazy-loading image processing logic, affecting all versions up to 3.1.14.

    0000073
    56.8K followersView on X

Explore more