Impact
The vulnerability allows an authenticated administrator to trigger arbitrary outbound HTTP requests through the plugin’s 'page_url' parameter, enabling the attacker to read or modify internal services. This results in potential data exposure, internal network compromise, or disruption of services, and is classified as CWE‑918, Server Side Request Forgery.
Affected Systems
The affected product is the Asset CleanUp: Page Speed Booster plugin for WordPress by gabelivan. Versions up to and including 1.4.0.5 are impacted. The flaw only exists when the administrators have changed the dom_get_type setting to 'wp_remote_post'.
Risk and Exploitability
With a CVSS score of 5.5, the vulnerability falls into the medium severity category. The EPSS metric is not available and the asset is not listed in the KEV catalog, indicating no publicly known exploit at the time of assessment. An attacker must possess administrator privileges and the ability to manipulate plugin settings to exploit this SSRF path, making the attack window somewhat narrow but still significant for sites that expose internal services.
OpenCVE Enrichment