Description
Unauthenticated Cross Site Request Forgery (CSRF) in Asset CleanUp: Page Speed Booster <= 1.4.0.5 versions.
Published: 2026-09-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated Cross Site Request Forgery (CSRF)
Action: Immediate Patch
AI Analysis

Impact

Untrusted users can perform arbitrary state‑changing requests against the WordPress Asset CleanUp: Page Speed Booster plugin because the plugin skips CSRF validation for unauthenticated requests. This flaw permits a malicious actor to modify plugin settings or otherwise influence the site's behavior without the user’s knowledge, compromising confidentiality and integrity of site configuration.

Affected Systems

All WordPress installations running the Asset CleanUp: Page Speed Booster plugin version 1.4.0.5 or earlier are affected. The plugin is provided by Gabe Livan and is commonly used to optimize page loading speeds.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.1, indicating a high severity. The EPSS score is not available, so the likelihood of exploitation cannot be quantified. The flaw is not listed in the CISA KEV catalog. Attackers can exploit it via normal web traffic; any user’s browser that is authenticated to the WordPress admin can be used to send forged requests. The lack of required privileges makes it a low‑barrier attack surface.

Generated by OpenCVE AI on September 17, 2026 at 21:23 UTC.

Remediation

Vendor Solution

Update the WordPress Asset CleanUp: Page Speed Booster Plugin to the latest available version (at least 1.4.0.6).


OpenCVE Recommended Actions

  • Upgrade the Asset CleanUp: Page Speed Booster plugin to version 1.4.0.6 or later. This release removes the CSRF validation flaw.
  • Temporarily disable the plugin from the WordPress admin dashboard until the patch is applied to prevent any state‑changing requests from unauthenticated users.
  • Restrict administrative access to the WordPress site via IP whitelisting or two‑factor authentication to reduce exposure to CSRF attacks.

Generated by OpenCVE AI on September 17, 2026 at 21:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Gabe Livan
Gabe Livan asset Cleanup: Page Speed Booster
Wordpress
Wordpress wordpress
Vendors & Products Gabe Livan
Gabe Livan asset Cleanup: Page Speed Booster
Wordpress
Wordpress wordpress

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Request Forgery (CSRF) in Asset CleanUp: Page Speed Booster <= 1.4.0.5 versions.
Title WordPress Asset CleanUp: Page Speed Booster plugin <= 1.4.0.5 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Gabe Livan Asset Cleanup: Page Speed Booster
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-17T14:41:12.773Z

Reserved: 2026-07-27T13:59:48.658Z

Link: CVE-2026-66571

cve-icon Vulnrichment

Updated: 2026-09-17T14:41:04.745Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:17:15.547

Modified: 2026-09-17T21:12:30.593

Link: CVE-2026-66571

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:30:18Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)