PT-2026-98380 · WordPress · Asset Cleanup: Page Speed Booster
CVE-2026-12037
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v3.1
5.5
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Asset CleanUp: Page Speed Booster versions prior to 1.4.0.6
Description
Server-Side Request Forgery occurs via the
page url parameter. Authenticated attackers with administrator-level access or higher can initiate web requests to arbitrary locations from the web application, potentially querying or modifying information from internal services. This issue is only exploitable if an administrator has configured the dom get type setting to wp remote post.Recommendations
Update Asset CleanUp: Page Speed Booster to version 1.4.0.6 or later.
As a temporary mitigation, avoid configuring the
dom get type setting to wp remote post.Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Asset Cleanup: Page Speed Booster