asset_cleanup_page_speed_booster vulnerabilities
CVEs whose affected-version data names the asset_cleanup_page_speed_booster package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-12037Medium· 5.5The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.0.5 via the 'page_url' parameter
The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.0.5 via the 'page_url' parameter. This makes it possible for authenticated attackers, with …
▾ Sunlitgabelivan · Asset CleanUp: Page Speed BoosterEPSS 0.29%via NVD
CVE-2026-13354High· 7.2The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 1.4.0.5 due to insufficient input sanitization and output escaping
The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 1.4.0.5 due to insufficient input sanitization and output escaping. This ma…
▾ Twilightgabelivan · Asset CleanUp: Page Speed BoosterEPSS 0.24%via NVD