Impact
The vulnerability allows an unauthenticated attacker to store malicious JavaScript in comment content within the Asset CleanUp: Page Speed Booster plugin. Insufficient input sanitization and output escaping mean that the script runs whenever a user views a page that includes the compromised comment. The flaw results in a classic stored XSS that can subvert user sessions, steal credentials, or deliver further payloads. It is limited to plugins where the setting combine_loaded_css is enabled, but any WordPress site with that feature turned on may become a vector. The impact is a full compromise of the affected site’s integrity and the potentially of phishing or malware delivery to all visitors.
Affected Systems
WordPress sites running the Asset CleanUp: Page Speed Booster plugin by gabelivan, versions up to and including 1.4.0.5 are affected. Sites using earlier releases or those that have upgraded past 1.4.0.5 are not impacted.
Risk and Exploitability
The CVSS score is 7.2, indicating high severity. The EPSS score is currently unavailable, and the vulnerability is not listed in CISA’s KEV catalog, but the lack of a protection mechanism and the unauthenticated nature of the flaw make exploitation likely on any site that enables combine_loaded_css. Attackers need only access a comment interface and can inject payloads that will execute for any user visiting the page where the comment appears. There are no known immediate defensive measures other than patching or disabling the enabled feature.
OpenCVE Enrichment