rootpwn

high · CVSS v3 7.2 · EPSS 0.00241

CVE-2026-13354

The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to inadequate sanitization

Overview

The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to inadequate sanitization of comment content. This flaw allows unauthenticated attackers to embed malicious scripts that execute in the browsers of users visiting affected pages.

Description

The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 1.4.0.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable on instances where combine_loaded_css has been enabled.

Impact

Successful exploitation compromises the integrity and confidentiality of user sessions, potentially leading to unauthorized administrative actions or data theft. The vulnerability affects all site visitors, including authenticated administrators, when viewing pages with malicious comment content. Impact is limited to environments where the 'combine_loaded_css' setting is active.

Remediation

Update the Asset CleanUp: Page Speed Booster plugin to version 1.4.0.6 or higher to ensure proper input sanitization. As a temporary mitigation, disable the 'Combine Loaded CSS' feature within the plugin settings to close the specific attack vector.

Risk context

This vulnerability is rated as High severity with a CVSS v3 score of 7.2, reflecting the risk of unauthenticated remote execution. While the EPSS score of 0.00241 indicates relatively low current exploitation activity, the ease of access for unauthenticated actors warrants prompt patching.

Affected products

  • WordPress
  • Asset CleanUp: Page Speed Booster plugin <= 1.4.0.5

Scores

Severity
high
CVSS v2
6.4
CVSS v3
7.2
CVSS v4
EPSS
0.00241

WordPress XSS Stored XSS Asset CleanUp Plugin Web Security

← All CVEs