WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro Autoptimize?

Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Autoptimize — verificado contra la base de datos de seguridad local de WP Clinic.

Qué hace este plugin

  • Slug: autoptimize
  • 800000+ instalaciones activas

core web vitalsimagesOptimizepagespeedperformance

Estado de mantenimiento

  • Última versión conocida: 3.1.15.1
  • Requiere PHP: 7.1+
  • PHP máximo soportado (analizado): 8.4

Vulnerabilidades conocidas

12 CVEs conocidos registrados para Autoptimize.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2026-3220 Autoptimize [autoptimize] < 3.1.15 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Desconocido < 3.1.15 3.1.15 2026-05-18 ✓ corregido en la última versión
CVE-2025-13401 Autoptimize [autoptimize] < 3.1.14 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,4 < 3.1.14 3.1.14 2025-12-03 ✓ corregido en la última versión
CVE-2023-2113 Autoptimize [autoptimize] < 3.1.7 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 4,8 < 3.1.7 3.1.7 2023-04-25 ✓ corregido en la última versión
Autoptimize [autoptimize] < 3.1.7 Desconocido < 3.1.7 3.1.7 2023-04-23 ✓ corregido en la última versión
CVE-2022-4057 Autoptimize [autoptimize] < 3.1.0 Solicitud directa (Forced Browsing / navegación forzada) Media 5,3 < 3.1.0 3.1.0 2022-12-05 ✓ corregido en la última versión
CVE-2022-2635 Autoptimize [autoptimize] < 3.1.1 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 4,8 < 3.1.1 3.1.1 2022-07-19 ✓ corregido en la última versión
CVE-2021-24332 Autoptimize [autoptimize] < 2.8.4 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 4,8 < 2.8.4 2.8.4 2021-05-07 ✓ corregido en la última versión
Autoptimize [autoptimize] < 2.8.4 Desconocido < 2.8.4 2.8.4 2021-05-04 ✓ corregido en la última versión

CVE-2026-3220

The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer WordPress plugin before 7.7.9 are vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. This allows an attacker to inject arbitrary HTML attributes in the final HTML output by anticipating the placeholder format.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2025-13401

The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the LCP Image to preload metabox in all versions up to, and including, 3.1.13 due to insufficient input sanitization and output escaping on user-supplied image attributes in the "create_img_preload_tag" function. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2023-2113

The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the critical css rules in versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Autoptimize [autoptimize] < 3.1.7

Update the WordPress Autoptimize plugin to the latest available version (at least 3.1.7). An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Autoptimize Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.1.7.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2022-4057

The Autoptimize plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.0.4 via the 'ao_ccss_export_callback' and 'ao_ccss_import_callback' functions. The settings.json file is not deleted in the import/export callbacks, which could lead to the settings options being leaked. This can allow unauthenticated attackers to extract sensitive data about the plugin's settings.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2022-2635

The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the critical css settings rules in versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. The issue was partially fixed in version 3.1.0 but a full fix was not made available until version 3.1.1.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2021-24332

The Autoptimize WordPress plugin before 2.8.4 was missing proper escaping and sanitisation in some of its settings, allowing high privilege users to set XSS payloads in them, leading to stored Cross-Site Scripting issues.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Autoptimize [autoptimize] < 2.8.4

Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by m0ze in WordPress Autoptimize plugin (versions <= 2.8.3).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

+ 8 vulnerabilidades conocidas más
CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2021-24378 Autoptimize [autoptimize] < 2.7.8 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 4,8 < 2.7.8 2.7.8 2020-10-09 ✓ corregido en la última versión
CVE-2021-24376 Autoptimize [autoptimize] < 2.7.8 Carga de archivos sin restricción de tipo peligroso Crítica 9,8 < 2.7.8 2.7.8 2020-10-09 ✓ corregido en la última versión
CVE-2021-24377 Autoptimize [autoptimize] < 2.7.8 Ejecución concurrente con recursos compartidos y sincronización incorrecta (condición de carrera / race condition) Alta 8,1 < 2.7.8 2.7.8 2020-10-09 ✓ corregido en la última versión
CVE-2020-24948 Autoptimize [autoptimize] < 2.7.7 Carga de archivos sin restricción de tipo peligroso Alta 7,2 < 2.7.7 2.7.7 2020-08-24 ✓ corregido en la última versión
Autoptimize [autoptimize] < 2.1.1 Desconocido < 2.1.1 2.1.1 2017-06-19 ✓ corregido en la última versión
CVE-2026-2352 Autoptimize [autoptimize] < 3.1.15 Desconocido < 3.1.15 3.1.15 0000-00-00 ✓ corregido en la última versión
CVE-2026-2430 Autoptimize [autoptimize] < 3.1.15 Desconocido < 3.1.15 3.1.15 0000-00-00 ✓ corregido en la última versión
Autoptimize [autoptimize] < 3.1.0 Desconocido < 3.1.0 3.1.0 ✓ corregido en la última versión

CVE-2021-24378

The Autoptimize WordPress plugin before 2.7.8 does not check for malicious files such as .html in the archive uploaded via the 'Import Settings' feature. As a result, it is possible for a high privilege user to upload a malicious file containing JavaScript code inside an archive which will execute when a victim visits index.html inside the plugin directory.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2021-24376

The Autoptimize WordPress plugin before 2.7.8 attempts to delete malicious files (such as .php) form the uploaded archive via the "Import Settings" feature, after its extraction. However, the extracted folders are not checked and it is possible to upload a zip which contained a directory with PHP file in it and then it is not removed from the disk. It is a bypass of CVE-2020-24948 which allows sending a PHP file via the "Import Settings" functionality to achieve Remote Code Execution.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2021-24377

The Autoptimize WordPress plugin before 2.7.8 attempts to remove potential malicious files from the extracted archive uploaded via the 'Import Settings' feature, however this is not sufficient to protect against RCE as a race condition can be achieved in between the moment the file is extracted on the disk but not yet removed. It is a bypass of CVE-2020-24948.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2020-24948

The ao_ccss_import AJAX call in Autoptimize Wordpress Plugin 2.7.6 does not ensure that the file provided is a legitimate Zip file, allowing high privilege users to upload arbitrary files, such as PHP, leading to remote command execution.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Autoptimize [autoptimize] < 2.1.1

The Autoptimize plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.0. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included. This requires both JS and CSS aggregation, and the 'Also aggregate inline CSS' option to be set.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2026-2352

The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ao_post_preload' meta value in all versions up to, and including, 3.1.14. This is due to insufficient input sanitization in the `ao_metabox_save()` function and missing output escaping when the value is rendered into a `<link>` tag in `autoptimizeImages.php`. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page, granted the "Image optimization" or "Lazy-load images" setting is enabled in the plugin configuration.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2026-2430

The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the lazy-loading image processing in all versions up to, and including, 3.1.14. This is due to the use of an overly permissive regular expression in the `add_lazyload` function that replaces all occurrences of `\ssrc=` in image tags without limiting to the actual attribute. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page by crafting an image tag where the `src` URL contains a space followed by `src=`, causing the regex to break the HTML structure and promote text inside attribute values into executable HTML attributes.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Autoptimize [autoptimize] < 3.1.0

Update the WordPress Autoptimize plugin to the latest available version (at least 3.1.0). Raad Haddad (Cloudyrion GmbH) discovered and reported this Sensitive Data Exposure vulnerability in WordPress Autoptimize Plugin. This vulnerability has been fixed in version 3.1.0.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Cómo solucionarlo

Mantén Autoptimize actualizado — 3.1.15.1 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.