Missing Authorization Vulnerability in Asset CleanUp: Page Speed Booster Plugin by Gabe Livan
CVE-2026-45212
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 12 May 2026
What is CVE-2026-45212?
A missing authorization vulnerability has been identified in the Asset CleanUp: Page Speed Booster plugin developed by Gabe Livan. This issue allows attackers to exploit incorrectly configured access control levels within the plugin, potentially leading to unauthorized actions that could compromise the integrity of the website. Users of versions from the release until 1.4.0.3 are advised to evaluate their security settings and apply necessary updates to mitigate any risk.
Affected Version(s)
Asset CleanUp: Page Speed Booster 0 <= 1.4.0.3
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Trương Hữu Phúc (truonghuuphuc) | Patchstack Bug Bounty Program