CVE-2022-2635
The Autoptimize plugin is susceptible to stored cross-site scripting through its critical CSS settings feature in versions up to 3.1.0 because it fails to properly sanitize inputs and escape outputs. Administrators and higher-privileged users can inject malicious scripts that persist and execute when other users view affected pages, though this vulnerability only manifests in multisite WordPress installations or environments where the unfiltered_html capability has been restricted. A partial mitigation appeared in version 3.1.0, with complete remediation delivered in version 3.1.1.
Based on public CVE data (MITRE/NVD).