<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Autoptimize - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/autoptimize/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 10:39:48 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/autoptimize/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored Cross-Site Scripting in Autoptimize WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-autoptimize-xss/</link><pubDate>Thu, 01 Oct 2026 10:39:48 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-autoptimize-xss/</guid><description>The Autoptimize WordPress plugin is vulnerable to Stored Cross-Site Scripting (XSS) due to improper sanitization of the REQUEST_URI path, allowing unauthenticated attackers to execute arbitrary scripts in the context of user sessions.</description><content:encoded><![CDATA[<p>The Autoptimize plugin for WordPress (versions 3.1.15.1 and earlier) contains a security flaw in how it handles the REQUEST_URI path, resulting in a Stored Cross-Site Scripting (XSS) vulnerability. An unauthenticated attacker can exploit this by crafting malicious requests that include JavaScript payloads within the URI path. For the injection to succeed, the 'Critical CSS' feature must be active, and a valid API key must be configured in the plugin settings. These conditions trigger the ao_ccss_enqueue() function, which processes the malicious URI and stores the payload. When an administrative or authenticated user subsequently visits the affected page, the stored script executes in their browser, potentially leading to unauthorized actions, account takeover, or session hijacking.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to inject malicious scripts into WordPress sites using the Autoptimize plugin. If the payload executes in the context of an administrator, the attacker could gain full control over the WordPress instance. This vulnerability affects any environment where the Critical CSS feature is enabled, posing a high risk for websites that rely on the plugin for front-end optimization.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update the Autoptimize plugin to a version greater than 3.1.15.1 to remediate CVE-2026-14995. If an immediate update is not feasible, disable the 'Critical CSS' feature in the plugin settings to mitigate the primary vector for unauthenticated exploitation until patching is complete. Monitor web access logs for unusual requests where the URI path contains script tags or common XSS payloads, focusing on POST requests targeted at the plugin's enqueue endpoint.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>