Executive brief
Asset CleanUp is a WordPress plugin that optimizes website performance by managing and removing unnecessary CSS and JavaScript files. An unauthenticated cross-site request forgery (CSRF) vulnerability allows attackers to trick logged-in administrators into performing unintended actions, such as changing plugin settings or disabling security features, by visiting a malicious webpage.
Technical details
The vulnerability is a cross-site request forgery (CSRF) flaw in Asset CleanUp: Page Speed Booster versions 1.4.0.5 and earlier. CSRF attacks exploit the trust a web application has in a user's browser by forging requests to perform actions without the user's knowledge or consent. Although the vulnerability is classified as unauthenticated, successful exploitation requires a logged-in user (administrator) to visit a malicious page or click a crafted link, which then triggers unintended actions within the WordPress admin panel. The vulnerability was patched in version 1.4.0.6.
Affected products
- <UNKNOWN> Asset CleanUp: Page Speed Booster <=1.4.0.5
Timeline
- 2026-07-27: disclosed: Reported by Helder Gonçalves
- 2026-09-17: advisory: Published by Patchstack
- 2026-09-17: patched: Fix available in version 1.4.0.6