Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Autoptimize — verificado contra la base de datos de seguridad local de WP Clinic.
Qué hace este plugin
- Slug:
autoptimize
- 800000+ instalaciones activas
core web vitalsimagesOptimizepagespeedperformance
Estado de mantenimiento
- Última versión conocida: 3.1.15.1
- Requiere PHP: 7.1+
- PHP máximo soportado (analizado): 8.4
Vulnerabilidades conocidas
12 CVEs conocidos registrados para Autoptimize.
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2026-3220
|
Autoptimize [autoptimize] < 3.1.15 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Desconocido
|
< 3.1.15
|
3.1.15 |
2026-05-18 |
✓ corregido en la última versión
|
|
CVE-2025-13401
|
Autoptimize [autoptimize] < 3.1.14 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,4
|
< 3.1.14
|
3.1.14 |
2025-12-03 |
✓ corregido en la última versión
|
|
CVE-2023-2113
|
Autoptimize [autoptimize] < 3.1.7 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
4,8
|
< 3.1.7
|
3.1.7 |
2023-04-25 |
✓ corregido en la última versión
|
|
—
|
Autoptimize [autoptimize] < 3.1.7 |
— |
Desconocido
|
< 3.1.7
|
3.1.7 |
2023-04-23 |
✓ corregido en la última versión
|
|
CVE-2022-4057
|
Autoptimize [autoptimize] < 3.1.0 |
Solicitud directa (Forced Browsing / navegación forzada) |
Media
5,3
|
< 3.1.0
|
3.1.0 |
2022-12-05 |
✓ corregido en la última versión
|
|
CVE-2022-2635
|
Autoptimize [autoptimize] < 3.1.1 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
4,8
|
< 3.1.1
|
3.1.1 |
2022-07-19 |
✓ corregido en la última versión
|
|
CVE-2021-24332
|
Autoptimize [autoptimize] < 2.8.4 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
4,8
|
< 2.8.4
|
2.8.4 |
2021-05-07 |
✓ corregido en la última versión
|
|
—
|
Autoptimize [autoptimize] < 2.8.4 |
— |
Desconocido
|
< 2.8.4
|
2.8.4 |
2021-05-04 |
✓ corregido en la última versión
|
CVE-2026-3220
The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer WordPress plugin before 7.7.9 are vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. This allows an attacker to inject arbitrary HTML attributes in the final HTML output by anticipating the placeholder format.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2025-13401
The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the LCP Image to preload metabox in all versions up to, and including, 3.1.13 due to insufficient input sanitization and output escaping on user-supplied image attributes in the "create_img_preload_tag" function. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2023-2113
The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the critical css rules in versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Autoptimize [autoptimize] < 3.1.7
Update the WordPress Autoptimize plugin to the latest available version (at least 3.1.7).
An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Autoptimize Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.1.7.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2022-4057
The Autoptimize plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.0.4 via the 'ao_ccss_export_callback' and 'ao_ccss_import_callback' functions. The settings.json file is not deleted in the import/export callbacks, which could lead to the settings options being leaked. This can allow unauthenticated attackers to extract sensitive data about the plugin's settings.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2022-2635
The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the critical css settings rules in versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. The issue was partially fixed in version 3.1.0 but a full fix was not made available until version 3.1.1.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2021-24332
The Autoptimize WordPress plugin before 2.8.4 was missing proper escaping and sanitisation in some of its settings, allowing high privilege users to set XSS payloads in them, leading to stored Cross-Site Scripting issues.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Autoptimize [autoptimize] < 2.8.4
Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by m0ze in WordPress Autoptimize plugin (versions <= 2.8.3).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
+ 8 vulnerabilidades conocidas más
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2021-24378
|
Autoptimize [autoptimize] < 2.7.8 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
4,8
|
< 2.7.8
|
2.7.8 |
2020-10-09 |
✓ corregido en la última versión
|
|
CVE-2021-24376
|
Autoptimize [autoptimize] < 2.7.8 |
Carga de archivos sin restricción de tipo peligroso |
Crítica
9,8
|
< 2.7.8
|
2.7.8 |
2020-10-09 |
✓ corregido en la última versión
|
|
CVE-2021-24377
|
Autoptimize [autoptimize] < 2.7.8 |
Ejecución concurrente con recursos compartidos y sincronización incorrecta (condición de carrera / race condition) |
Alta
8,1
|
< 2.7.8
|
2.7.8 |
2020-10-09 |
✓ corregido en la última versión
|
|
CVE-2020-24948
|
Autoptimize [autoptimize] < 2.7.7 |
Carga de archivos sin restricción de tipo peligroso |
Alta
7,2
|
< 2.7.7
|
2.7.7 |
2020-08-24 |
✓ corregido en la última versión
|
|
—
|
Autoptimize [autoptimize] < 2.1.1 |
— |
Desconocido
|
< 2.1.1
|
2.1.1 |
2017-06-19 |
✓ corregido en la última versión
|
|
CVE-2026-2352
|
Autoptimize [autoptimize] < 3.1.15 |
— |
Desconocido
|
< 3.1.15
|
3.1.15 |
0000-00-00 |
✓ corregido en la última versión
|
|
CVE-2026-2430
|
Autoptimize [autoptimize] < 3.1.15 |
— |
Desconocido
|
< 3.1.15
|
3.1.15 |
0000-00-00 |
✓ corregido en la última versión
|
|
—
|
Autoptimize [autoptimize] < 3.1.0 |
— |
Desconocido
|
< 3.1.0
|
3.1.0 |
— |
✓ corregido en la última versión
|
CVE-2021-24378
The Autoptimize WordPress plugin before 2.7.8 does not check for malicious files such as .html in the archive uploaded via the 'Import Settings' feature. As a result, it is possible for a high privilege user to upload a malicious file containing JavaScript code inside an archive which will execute when a victim visits index.html inside the plugin directory.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2021-24376
The Autoptimize WordPress plugin before 2.7.8 attempts to delete malicious files (such as .php) form the uploaded archive via the "Import Settings" feature, after its extraction. However, the extracted folders are not checked and it is possible to upload a zip which contained a directory with PHP file in it and then it is not removed from the disk. It is a bypass of CVE-2020-24948 which allows sending a PHP file via the "Import Settings" functionality to achieve Remote Code Execution.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2021-24377
The Autoptimize WordPress plugin before 2.7.8 attempts to remove potential malicious files from the extracted archive uploaded via the 'Import Settings' feature, however this is not sufficient to protect against RCE as a race condition can be achieved in between the moment the file is extracted on the disk but not yet removed. It is a bypass of CVE-2020-24948.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2020-24948
The ao_ccss_import AJAX call in Autoptimize Wordpress Plugin 2.7.6 does not ensure that the file provided is a legitimate Zip file, allowing high privilege users to upload arbitrary files, such as PHP, leading to remote command execution.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
Autoptimize [autoptimize] < 2.1.1
The Autoptimize plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.0. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included. This requires both JS and CSS aggregation, and the 'Also aggregate inline CSS' option to be set.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2026-2352
The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ao_post_preload' meta value in all versions up to, and including, 3.1.14. This is due to insufficient input sanitization in the `ao_metabox_save()` function and missing output escaping when the value is rendered into a `<link>` tag in `autoptimizeImages.php`. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page, granted the "Image optimization" or "Lazy-load images" setting is enabled in the plugin configuration.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2026-2430
The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the lazy-loading image processing in all versions up to, and including, 3.1.14. This is due to the use of an overly permissive regular expression in the `add_lazyload` function that replaces all occurrences of `\ssrc=` in image tags without limiting to the actual attribute. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page by crafting an image tag where the `src` URL contains a space followed by `src=`, causing the regex to break the HTML structure and promote text inside attribute values into executable HTML attributes.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Autoptimize [autoptimize] < 3.1.0
Update the WordPress Autoptimize plugin to the latest available version (at least 3.1.0).
Raad Haddad (Cloudyrion GmbH) discovered and reported this Sensitive Data Exposure vulnerability in WordPress Autoptimize Plugin. This vulnerability has been fixed in version 3.1.0.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Cómo solucionarlo
Mantén Autoptimize actualizado — 3.1.15.1 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.
Alternativas más seguras / más establecidas