Executive brief
Asset CleanUp: Page Speed Booster, a WordPress plugin used to optimize website performance, contains a security flaw in its access control settings. This vulnerability allows unauthenticated users to perform actions that should be restricted to administrators, potentially impacting the availability or configuration of the site's performance settings. While the impact is considered low, it could allow unauthorized changes to how the website loads assets.
Technical details
A missing authorization vulnerability (CWE-862) exists in the Asset CleanUp: Page Speed Booster plugin for WordPress in versions up to and including 1.4.0.3. The flaw stems from incorrectly configured access control security levels, which fail to properly validate user permissions before executing certain functions. An unauthenticated remote attacker can exploit this to trigger actions that should require higher privileges. According to the CVSS vector, the primary impact is on availability (A:L), suggesting an attacker might be able to disrupt plugin functionality or site performance settings. The issue is resolved in version 1.4.0.4.
Affected products
- Gabe Livan Asset CleanUp: Page Speed Booster <= 1.4.0.3
Timeline
- 2026-02-05: other: Vulnerability reported by researcher
- 2026-03-07: disclosed: Initial disclosure by Patchstack
- 2026-03-07: patched: Patch released in version 1.4.0.4
- 2026-05-12: advisory: NVD publication date