Vulnerabilities and security researches forwp-asset-clean-up wp-asset-clean-up
Direction: ascendingJun 06, 2024
Asset CleanUp: Page Speed Booster # CVE-2021-24937
- CVE, Research URL
- Home page URL
- Application
- Date
- Feb 01, 2022
- Research Description
- The Asset CleanUp: Page Speed Booster WordPress plugin before 1.3.8.5 does not escape the wpacu_selected_sub_tab_area parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting issue
- Affected versions
-
max 1.3.8.5.
- Status
-
vulnerable
Asset CleanUp: Page Speed Booster # CVE-2021-24983
- CVE, Research URL
- Home page URL
- Application
- Date
- Feb 01, 2022
- Research Description
- The Asset CleanUp: Page Speed Booster WordPress plugin before 1.3.8.5 does not sanitise and escape POSted parameters sent to the wpassetcleanup_fetch_active_plugins_icons AJAX action (available to admin users), leading to a Reflected Cross-Site Scripting issue
- Affected versions
-
max 1.3.8.5.
- Status
-
vulnerable
Asset CleanUp: Page Speed Booster # CVE-2021-36899
- CVE, Research URL
- Home page URL
- Application
- Date
- Oct 11, 2022
- Research Description
- Authenticated (admin+) Reflected Cross-Site Scripting (XSS) vulnerability in Gabe Livan's Asset CleanUp: Page Speed Booster plugin <= 1.3.8.4 at WordPress.
- Affected versions
-
max 1.3.8.5.
- Status
-
vulnerable
Aug 20, 2024
Asset CleanUp: Page Speed Booster # CVE-2024-43314
- CVE, Research URL
- Home page URL
- Application
- Date
- Nov 01, 2024
- Research Description
- Missing Authorization vulnerability in Gabe Livan Asset CleanUp: Page Speed Booster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Asset CleanUp: Page Speed Booster: from n/a through 1.3.9.3.
- Affected versions
-
max 1.3.9.4.
- Status
-
vulnerable
Dec 02, 2024
Asset CleanUp: Page Speed Booster # CVE-2024-53738
- CVE, Research URL
- Home page URL
- Application
- Date
- Dec 01, 2024
- Research Description
- Server-Side Request Forgery (SSRF) vulnerability in Gabe Livan Asset CleanUp: Page Speed Booster wp-asset-clean-up allows Server Side Request Forgery.This issue affects Asset CleanUp: Page Speed Booster: from n/a through <= 1.3.9.8.
- Affected versions
-
max 1.3.9.9.
- Status
-
vulnerable
May 13, 2026
Asset CleanUp: Page Speed Booster # CVE-2026-45212
- CVE, Research URL
- Home page URL
- Application
- Date
- May 12, 2026
- Research Description
- Missing Authorization vulnerability in Gabe Livan Asset CleanUp: Page Speed Booster wp-asset-clean-up allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Asset CleanUp: Page Speed Booster: from n/a through <= 1.4.0.3.
- Affected versions
-
max 1.4.0.4.
- Status
-
vulnerable
Jun 16, 2026
Asset CleanUp: Page Speed Booster # 9605d265a00b78bcfc2579aba8b58eb9b22de4d7
- CVE, Research URL
- Home page URL
- Application
- Date
- Apr 20, 2015
- Research Description
- Asset CleanUp: Page Speed Booster [wp-asset-clean-up] < 1.3.6.7 Asset CleanUp: Page Speed Booster <= 1.3.6.6 - Reflected Cross-Site Scripting The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the tab parameter in versions up to, and including 1.3.6.6 due to insufficient input sanitization and output escaping on add_query_arg and remove_query_arg. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in administrative pages that execute if they can successfully trick a site administrator into performing an action such as clicking on a link.
- Affected versions
-
max 1.3.6.7.
- Status
-
vulnerable
Asset CleanUp: Page Speed Booster # d066e4eb260d30b1c0b5883d5a6caeca97951ee3
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 09, 2020
- Research Description
- Asset CleanUp: Page Speed Booster [wp-asset-clean-up] < 1.3.6.7 WordPress Asset CleanUp: Page Speed Booster plugin <= 1.3.6.6 - Reflected Cross-Site Scripting (XSS) vulnerability Reflected Cross-Site Scripting (XSS) vulnerability found by Antony Garand (Sucuri) in WordPress Asset CleanUp: Page Speed Booster plugin (versions <= 1.3.6.6).
- Affected versions
-
max 1.3.6.7.
- Status
-
vulnerable
Asset CleanUp: Page Speed Booster # c837ba54-6e53-49eb-ab5c-68b955db4f36
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- Asset CleanUp: Page Speed Booster [wp-asset-clean-up] < 1.3.6.7 Asset CleanUp: Page Speed Booster < 1.3.6.7 - CSRF & XSS Antony Garand of Sucuri discovered that multiple WordPress plugins were vulnerable to Cross-Site Scripting (XSS) within the admin panel, which could be exploited by using s Cross-Site Request Forgery (CSRF) attack.
- Affected versions
-
max 1.3.6.7.
- Status
-
vulnerable
Sep 19, 2026
Asset CleanUp: Page Speed Booster # CVE-2026-66571
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 17, 2026
- Research Description
- Unauthenticated Cross Site Request Forgery (CSRF) in Asset CleanUp: Page Speed Booster <= 1.4.0.5 versions.
- Affected versions
-
max 1.4.0.6.
- Status
-
vulnerable
Sep 20, 2026
Asset CleanUp: Page Speed Booster # CVE-2026-13354
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 19, 2026
- Research Description
- The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 1.4.0.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable on instances where combine_loaded_css has been enabled.
- Affected versions
-
max 1.4.0.6.
- Status
-
vulnerable
Sep 25, 2026
Asset CleanUp: Page Speed Booster # CVE-2026-12037
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 25, 2026
- Research Description
- The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.0.5 via the 'page_url' parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. This vulnerability is only reachable when the plugin's dom_get_type setting has been configured to 'wp_remote_post' by an administrator.
- Affected versions
-
max 1.4.0.6.
- Status
-
vulnerable