Server-Side Request Forgery Vulnerability in Asset CleanUp: Page Speed Booster for WordPress
CVE-2026-12037
5.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 September 2026
What is CVE-2026-12037?
The Asset CleanUp: Page Speed Booster plugin for WordPress contains a Server-Side Request Forgery vulnerability affecting all versions up to 1.4.0.5. This issue allows authenticated users with administrator-level access to exploit the 'page_url' parameter, enabling them to send web requests to untrusted locations. When the plugin's 'dom_get_type' setting is configured to 'wp_remote_post', attackers can potentially gain access to internal services, leading to unauthorized information retrieval and modification.
Affected Version(s)
Asset CleanUp: Page Speed Booster 0 <= 1.4.0.5