Asset CleanUp: Page Speed Booster permits forged cross-site requests
Asset CleanUp: Page Speed Booster through 1.4.0.5 is affected by CSRF: an attacker needs no account but must induce victim interaction so a request is sent in the victim's browser context. The export does not name the endpoint, action, parameters, required victim role or operation performed. Its CNA vector reports limited confidentiality, integrity and availability impact with a changed scope; it does not establish a particular data disclosure, setting change or destructive action. The affected-version data marks 1.4.0.6 unaffected.
- Component
- Asset CleanUp: Page Speed Booster
- Plugin slug
wp-asset-clean-up- Affected
- n/a through 1.4.0.5
- Safe version
1.4.0.6- Published
- Sep 17, 2026
This CVE was published Sep 17, 2026 and is one of 5 known issues for this plugin.
Update, patch or deactivate.
Update Asset CleanUp: Page Speed Booster to 1.4.0.6 or later. Require an action-bound CSRF token on state-changing requests and validate the caller's capability and target authorization independently. Do not permit sensitive operations through unprotected requests or treat login alone as proof of user intent.
A safe version is available, so updating to that version or later is the preferred remediation. If an immediate update is not practical, consider a targeted application patch or temporarily restricting the affected functionality.
Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.
Technical description
Unauthenticated Cross Site Request Forgery (CSRF) in Asset CleanUp: Page Speed Booster <= 1.4.0.5 versions.
CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L