Impact
Untrusted users can perform arbitrary state‑changing requests against the WordPress Asset CleanUp: Page Speed Booster plugin because the plugin skips CSRF validation for unauthenticated requests. This flaw permits a malicious actor to modify plugin settings or otherwise influence the site's behavior without the user’s knowledge, compromising confidentiality and integrity of site configuration.
Affected Systems
All WordPress installations running the Asset CleanUp: Page Speed Booster plugin version 1.4.0.5 or earlier are affected. The plugin is provided by Gabe Livan and is commonly used to optimize page loading speeds.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.1, indicating a high severity. The EPSS score is not available, so the likelihood of exploitation cannot be quantified. The flaw is not listed in the CISA KEV catalog. Attackers can exploit it via normal web traffic; any user’s browser that is authenticated to the WordPress admin can be used to send forged requests. The lack of required privileges makes it a low‑barrier attack surface.
OpenCVE Enrichment