cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forwp-asset-clean-up wp-asset-clean-up

Direction: ascending
Jun 06, 2024

Asset CleanUp: Page Speed Booster # CVE-2021-24937

CVE, Research URL

CVE-2021-24937

Date
Feb 01, 2022
Research Description
The Asset CleanUp: Page Speed Booster WordPress plugin before 1.3.8.5 does not escape the wpacu_selected_sub_tab_area parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting issue
Affected versions
max 1.3.8.5.
Status
vulnerable

Asset CleanUp: Page Speed Booster # CVE-2021-24983

CVE, Research URL

CVE-2021-24983

Date
Feb 01, 2022
Research Description
The Asset CleanUp: Page Speed Booster WordPress plugin before 1.3.8.5 does not sanitise and escape POSted parameters sent to the wpassetcleanup_fetch_active_plugins_icons AJAX action (available to admin users), leading to a Reflected Cross-Site Scripting issue
Affected versions
max 1.3.8.5.
Status
vulnerable

Asset CleanUp: Page Speed Booster # CVE-2021-36899

CVE, Research URL

CVE-2021-36899

Date
Oct 11, 2022
Research Description
Authenticated (admin+) Reflected Cross-Site Scripting (XSS) vulnerability in Gabe Livan's Asset CleanUp: Page Speed Booster plugin <= 1.3.8.4 at WordPress.
Affected versions
max 1.3.8.5.
Status
vulnerable
Aug 20, 2024

Asset CleanUp: Page Speed Booster # CVE-2024-43314

CVE, Research URL

CVE-2024-43314

Date
Nov 01, 2024
Research Description
Missing Authorization vulnerability in Gabe Livan Asset CleanUp: Page Speed Booster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Asset CleanUp: Page Speed Booster: from n/a through 1.3.9.3.
Affected versions
max 1.3.9.4.
Status
vulnerable
Dec 02, 2024

Asset CleanUp: Page Speed Booster # CVE-2024-53738

CVE, Research URL

CVE-2024-53738

Date
Dec 01, 2024
Research Description
Server-Side Request Forgery (SSRF) vulnerability in Gabe Livan Asset CleanUp: Page Speed Booster wp-asset-clean-up allows Server Side Request Forgery.This issue affects Asset CleanUp: Page Speed Booster: from n/a through <= 1.3.9.8.
Affected versions
max 1.3.9.9.
Status
vulnerable
May 13, 2026

Asset CleanUp: Page Speed Booster # CVE-2026-45212

CVE, Research URL

CVE-2026-45212

Date
May 12, 2026
Research Description
Missing Authorization vulnerability in Gabe Livan Asset CleanUp: Page Speed Booster wp-asset-clean-up allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Asset CleanUp: Page Speed Booster: from n/a through <= 1.4.0.3.
Affected versions
max 1.4.0.4.
Status
vulnerable
Jun 16, 2026

Asset CleanUp: Page Speed Booster # 9605d265a00b78bcfc2579aba8b58eb9b22de4d7

Date
Apr 20, 2015
Research Description
Asset CleanUp: Page Speed Booster [wp-asset-clean-up] < 1.3.6.7 Asset CleanUp: Page Speed Booster <= 1.3.6.6 - Reflected Cross-Site Scripting The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the tab parameter in versions up to, and including 1.3.6.6 due to insufficient input sanitization and output escaping on add_query_arg and remove_query_arg. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in administrative pages that execute if they can successfully trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 1.3.6.7.
Status
vulnerable

Asset CleanUp: Page Speed Booster # d066e4eb260d30b1c0b5883d5a6caeca97951ee3

Date
Sep 09, 2020
Research Description
Asset CleanUp: Page Speed Booster [wp-asset-clean-up] < 1.3.6.7 WordPress Asset CleanUp: Page Speed Booster plugin <= 1.3.6.6 - Reflected Cross-Site Scripting (XSS) vulnerability Reflected Cross-Site Scripting (XSS) vulnerability found by Antony Garand (Sucuri) in WordPress Asset CleanUp: Page Speed Booster plugin (versions <= 1.3.6.6).
Affected versions
max 1.3.6.7.
Status
vulnerable

Asset CleanUp: Page Speed Booster # c837ba54-6e53-49eb-ab5c-68b955db4f36

Date
-
Research Description
Asset CleanUp: Page Speed Booster [wp-asset-clean-up] < 1.3.6.7 Asset CleanUp: Page Speed Booster &lt; 1.3.6.7 - CSRF &amp; XSS Antony Garand of Sucuri discovered that multiple WordPress plugins were vulnerable to Cross-Site Scripting (XSS) within the admin panel, which could be exploited by using s Cross-Site Request Forgery (CSRF) attack.
Affected versions
max 1.3.6.7.
Status
vulnerable
Sep 19, 2026

Asset CleanUp: Page Speed Booster # CVE-2026-66571

CVE, Research URL

CVE-2026-66571

Date
Sep 17, 2026
Research Description
Unauthenticated Cross Site Request Forgery (CSRF) in Asset CleanUp: Page Speed Booster <= 1.4.0.5 versions.
Affected versions
max 1.4.0.6.
Status
vulnerable
Sep 20, 2026

Asset CleanUp: Page Speed Booster # CVE-2026-13354

CVE, Research URL

CVE-2026-13354

Date
Sep 19, 2026
Research Description
The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 1.4.0.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable on instances where combine_loaded_css has been enabled.
Affected versions
max 1.4.0.6.
Status
vulnerable
Sep 25, 2026

Asset CleanUp: Page Speed Booster # CVE-2026-12037

CVE, Research URL

CVE-2026-12037

Date
Sep 25, 2026
Research Description
The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.0.5 via the 'page_url' parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. This vulnerability is only reachable when the plugin's dom_get_type setting has been configured to 'wp_remote_post' by an administrator.
Affected versions
max 1.4.0.6.
Status
vulnerable