WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Autoptimize

Autoptimize speeds up your website by optimizing JS, CSS, images (incl. lazy-load), HTML and Google Fonts, asyncing JS, removing emoji cruft and more.

12Reported vulnerabilities
9.8Highest CVSS score
3.1.15.1Latest version
800,000+Active installs

What to do now

Update Autoptimize to 3.1.15 or later. 12 of these have a fixed version available. Updating resolves them.

Plugin last updated: April 4, 2026 / Tested up to WordPress: 6.9.7 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2020-24948 High 7.2 13.1% Before 2.7.7 2.7.7 September 3, 2020
CVE-2021-24376 Critical 9.8 3.7% Before 2.7.8 2.7.8 June 21, 2021
CVE-2021-24377 High 8.1 1.2% Before 2.7.8 2.7.8 June 21, 2021
WF-0d4e3560-2208-4122-812e-0c506fe45126 Critical 9.8 2.1.0 and earlier 2.1.1 June 19, 2017
CVE-2023-2113 Medium 4.8 0.5% Before 3.1.7 3.1.7 May 30, 2023
CVE-2022-2635 Medium 4.8 0.5% Before 3.1.1 3.1.1 September 16, 2022
CVE-2021-24378 Medium 4.8 0.6% Before 2.7.8 2.7.8 June 21, 2021
CVE-2021-24332 Medium 4.8 0.6% Before 2.8.4 2.8.4 May 24, 2021
CVE-2026-3220 High 7.2 0.3% Before 3.1.15 3.1.15 April 27, 2026
CVE-2026-2352 Medium 6.4 0.3% 0 to 3.1.14 (inclusive) 3.1.15 March 21, 2026
CVE-2025-13401 Medium 6.4 0.3% 0 to 3.1.13 (inclusive) 3.1.14 December 3, 2025
CVE-2026-2430 Medium 6.4 0.2% 0 to 3.1.14 (inclusive) 3.1.15 March 21, 2026

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.