CVE-2026-66571: WordPress Asset CleanUp: Page Speed Booster plugin <= 1.4.0.5 - Cross Site Request Forgery (CSRF) vulnerability
Published Sep 17, 2026
·Updated
Unauthenticated Cross Site Request Forgery (CSRF) in Asset CleanUp: Page Speed Booster <= 1.4.0.5 versions.
Affected Software
1 affected component
wordpress/plugin/Asset CleanUp: Page Speed Booster<=1.4.0.5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/asset-cleanup-page-speed-boosterto a version that resolves this vulnerability.Fixed in 1.4.0.6
Event History
Sep 17, 2026
CVE Published
via MITRE·01:24 PM
Data Sourced
via MITRE·01:24 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who is exposed to this issue?
WordPress sites using the Asset CleanUp: Page Speed Booster plugin at version 1.4.0.5 or earlier are affected.
2
Does an attacker need an account on the WordPress site?
No. The issue is described as unauthenticated CSRF, so the attacker does not need to authenticate to the affected site.
3
What user interaction is required for exploitation?
The CVSS vector includes UI:R, indicating that exploitation requires user interaction.