CPE
The Autoptimize WordPress plugin is vulnerable to Stored Cross-Site Scripting (XSS) due to improper sanitization of the REQUEST_URI path, allowing unauthenticated attackers to execute arbitrary scripts in the context of user sessions.