Junglewise Threat Intelligence

CVE-2026-66571: Asset CleanUp: Page Speed Booster cross-site request forgery

CVE-2026-66571 · Severity: high · CVSS 7.1 · Published 2026-09-17

Vendors: Unknown.

Executive brief

Asset CleanUp is a WordPress plugin that optimizes website performance by managing and removing unnecessary CSS and JavaScript files. An unauthenticated cross-site request forgery (CSRF) vulnerability allows attackers to trick logged-in administrators into performing unintended actions, such as changing plugin settings or disabling security features, by visiting a malicious webpage.

Technical details

The vulnerability is a cross-site request forgery (CSRF) flaw in Asset CleanUp: Page Speed Booster versions 1.4.0.5 and earlier. CSRF attacks exploit the trust a web application has in a user's browser by forging requests to perform actions without the user's knowledge or consent. Although the vulnerability is classified as unauthenticated, successful exploitation requires a logged-in user (administrator) to visit a malicious page or click a crafted link, which then triggers unintended actions within the WordPress admin panel. The vulnerability was patched in version 1.4.0.6.

Affected products

  • <UNKNOWN> Asset CleanUp: Page Speed Booster <=1.4.0.5

Timeline

  • 2026-07-27: disclosed: Reported by Helder Gonçalves
  • 2026-09-17: advisory: Published by Patchstack
  • 2026-09-17: patched: Fix available in version 1.4.0.6

References