PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-12037 gabelivan CVE debrief

The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.0.5 via the 'page_url' parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. This vulnerability is only reachable when the plugin's dom_get_type setting has been configured to 'wp_remote_post' by an administrator.

Vendor
gabelivan
Product
Asset CleanUp: Page Speed Booster
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-25
Original CVE updated
2026-09-25
Advisory published
2026-09-25
Advisory updated
2026-09-25

Who should care

Administrators of WordPress installations using the Asset CleanUp: Page Speed Booster plugin should assess their exposure and take necessary actions to prevent exploitation. This includes verifying the plugin's configuration, restricting administrator-level access, and monitoring for suspicious web requests. Affected operators should prioritize vulnerability management and security teams should review compensating controls.

Why it matters

The CVE-2026-12037 vulnerability in the Asset CleanUp: Page Speed Booster plugin for WordPress allows authenticated attackers with administrator-level access to make web requests to arbitrary locations, potentially leading to information disclosure or modification. Defenders should verify the plugin's configuration and restrict access to prevent exploitation.

  • Authenticated attackers with administrator-level access can make web requests to arbitrary locations.
  • The vulnerability can be used to query and modify information from internal services.
  • The plugin's dom_get_type setting must be configured to 'wp_remote_post' for the vulnerability to be reachable.
  • Verification of the plugin's configuration and restriction of administrator-level access are necessary to prevent exploitation.

Technical summary

The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.0.5 via the 'page_url' parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

Defensive priority

Administrators of WordPress installations using the Asset CleanUp: Page Speed Booster plugin should verify that the plugin's dom_get_type setting is not configured to 'wp_remote_post' and restrict administrator-level access to prevent exploitation.

Recommended defensive actions

  • Verify that the plugin's dom_get_type setting is not configured to 'wp_remote_post'.
  • Restrict administrator-level access to the WordPress installation.
  • Monitor for suspicious web requests originating from the web application.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The vulnerability was reported by [email protected] and is described in the CVE Program record and the NVD vulnerability detail page. The reporter provided details on the plugin's configuration and the 'page_url' parameter vulnerability. Evidence is limited to public CVE Program and NVD records. Defenders should verify plugin configuration and restrict administrator-level access.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-12037 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-12037

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-12037 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-12037

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/wp-asset-clean-up/tags/1.4.0.3/classes/Admin/MainAdmin.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/wp-asset-clean-up/tags/1.4.0.4/classes/Admin/MainAdmin.php

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.