high · CVSS v3 7.2 · EPSS 0.00241
CVE-2026-13354
The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to inadequate sanitization
Overview
The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to inadequate sanitization of comment content. This flaw allows unauthenticated attackers to embed malicious scripts that execute in the browsers of users visiting affected pages.
Description
The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 1.4.0.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable on instances where combine_loaded_css has been enabled.
Impact
Successful exploitation compromises the integrity and confidentiality of user sessions, potentially leading to unauthorized administrative actions or data theft. The vulnerability affects all site visitors, including authenticated administrators, when viewing pages with malicious comment content. Impact is limited to environments where the 'combine_loaded_css' setting is active.
Remediation
Update the Asset CleanUp: Page Speed Booster plugin to version 1.4.0.6 or higher to ensure proper input sanitization. As a temporary mitigation, disable the 'Combine Loaded CSS' feature within the plugin settings to close the specific attack vector.
Risk context
This vulnerability is rated as High severity with a CVSS v3 score of 7.2, reflecting the risk of unauthenticated remote execution. While the EPSS score of 0.00241 indicates relatively low current exploitation activity, the ease of access for unauthenticated actors warrants prompt patching.
Affected products
- WordPress
- Asset CleanUp: Page Speed Booster plugin <= 1.4.0.5
Scores
- Severity
- high
- CVSS v2
- 6.4
- CVSS v3
- 7.2
- CVSS v4
- —
- EPSS
- 0.00241