CVE-2026-14995

CVE-2026-14995 published: The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI Path in all versions up to, and including, 3.1.15.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated atta...

View full NVD advisory → ← Back to CVE watch