WordPress security changelog
HIGH CVE-2026-66571 Deferred

Asset CleanUp: Page Speed Booster permits forged cross-site requests

Asset CleanUp: Page Speed Booster through 1.4.0.5 is affected by CSRF: an attacker needs no account but must induce victim interaction so a request is sent in the victim's browser context. The export does not name the endpoint, action, parameters, required victim role or operation performed. Its CNA vector reports limited confidentiality, integrity and availability impact with a changed scope; it does not establish a particular data disclosure, setting change or destructive action. The affected-version data marks 1.4.0.6 unaffected.

CVE / CNA score 7.1 CVSS 3.1 · audit@patchstack.com
NVD score Pending NVD has not published its own CVSS assessment.
Component
Asset CleanUp: Page Speed Booster
Plugin slug
wp-asset-clean-up
Affected
n/a through 1.4.0.5
Safe version
1.4.0.6
Published
Sep 17, 2026
Weakness
CWE-352 — Cross-Site Request Forgery (CSRF)

This CVE was published Sep 17, 2026 and is one of 5 known issues for this plugin.

Update, patch or deactivate.

Update Asset CleanUp: Page Speed Booster to 1.4.0.6 or later. Require an action-bound CSRF token on state-changing requests and validate the caller's capability and target authorization independently. Do not permit sensitive operations through unprotected requests or treat login alone as proof of user intent.

A safe version is available, so updating to that version or later is the preferred remediation. If an immediate update is not practical, consider a targeted application patch or temporarily restricting the affected functionality.

Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.

Technical description

Unauthenticated Cross Site Request Forgery (CSRF) in Asset CleanUp: Page Speed Booster <= 1.4.0.5 versions.

CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

Primary and upstream sources