Description
The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 1.4.0.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable on instances where combine_loaded_css has been enabled.
Published: 2026-09-19
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting causing arbitrary script execution via unauthenticated comment injection
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows an unauthenticated attacker to store malicious JavaScript in comment content within the Asset CleanUp: Page Speed Booster plugin. Insufficient input sanitization and output escaping mean that the script runs whenever a user views a page that includes the compromised comment. The flaw results in a classic stored XSS that can subvert user sessions, steal credentials, or deliver further payloads. It is limited to plugins where the setting combine_loaded_css is enabled, but any WordPress site with that feature turned on may become a vector. The impact is a full compromise of the affected site’s integrity and the potentially of phishing or malware delivery to all visitors.

Affected Systems

WordPress sites running the Asset CleanUp: Page Speed Booster plugin by gabelivan, versions up to and including 1.4.0.5 are affected. Sites using earlier releases or those that have upgraded past 1.4.0.5 are not impacted.

Risk and Exploitability

The CVSS score is 7.2, indicating high severity. The EPSS score is currently unavailable, and the vulnerability is not listed in CISA’s KEV catalog, but the lack of a protection mechanism and the unauthenticated nature of the flaw make exploitation likely on any site that enables combine_loaded_css. Attackers need only access a comment interface and can inject payloads that will execute for any user visiting the page where the comment appears. There are no known immediate defensive measures other than patching or disabling the enabled feature.

Generated by OpenCVE AI on September 19, 2026 at 10:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Asset CleanUp: Page Speed Booster plugin to the latest available release that addresses the XSS flaw.
  • If an immediate update is not possible, disable the combine_loaded_css setting to remove the vector that allows stored comments to be rendered with injected scripts.
  • Add a site‑wide input sanitization layer or use a security plugin to strip disallowed JavaScript from comment content to block the injection of malicious code.

Generated by OpenCVE AI on September 19, 2026 at 10:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Gabe Livan
Gabe Livan asset Cleanup: Page Speed Booster
Wordpress
Wordpress wordpress
Vendors & Products Gabe Livan
Gabe Livan asset Cleanup: Page Speed Booster
Wordpress
Wordpress wordpress

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Description The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 1.4.0.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable on instances where combine_loaded_css has been enabled.
Title Asset CleanUp: Page Speed Booster <= 1.4.0.5 - Unauthenticated Stored Cross-Site Scripting via Comment Content
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Gabe Livan Asset Cleanup: Page Speed Booster
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T14:01:27.429Z

Reserved: 2026-06-25T16:36:50.443Z

Link: CVE-2026-13354

cve-icon Vulnrichment

Updated: 2026-09-19T13:58:30.493Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T03:17:13.553

Modified: 2026-09-21T13:33:33.387

Link: CVE-2026-13354

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:45:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')