CVE-2021-24378
The Autoptimize plugin before version 2.7.8 fails to validate file types within archives uploaded through its Import Settings functionality. This oversight allows authenticated users with elevated privileges to embed malicious files like HTML documents containing JavaScript into an archive, which subsequently executes when users access the resulting file within the plugin's directory. The vulnerability requires high-level user access but poses a cross-site scripting risk through the imported archive contents.
Based on public CVE data (MITRE/NVD).