PatchSiren cyber security CVE debrief
CVE-2026-12037 gabelivan CVE debrief
The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.0.5 via the 'page_url' parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. This vulnerability is only reachable when the plugin's dom_get_type setting has been configured to 'wp_remote_post' by an administrator.
- Vendor
- gabelivan
- Product
- Asset CleanUp: Page Speed Booster
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-25
- Original CVE updated
- 2026-09-25
- Advisory published
- 2026-09-25
- Advisory updated
- 2026-09-25
Who should care
Administrators of WordPress installations using the Asset CleanUp: Page Speed Booster plugin should assess their exposure and take necessary actions to prevent exploitation. This includes verifying the plugin's configuration, restricting administrator-level access, and monitoring for suspicious web requests. Affected operators should prioritize vulnerability management and security teams should review compensating controls.
Why it matters
The CVE-2026-12037 vulnerability in the Asset CleanUp: Page Speed Booster plugin for WordPress allows authenticated attackers with administrator-level access to make web requests to arbitrary locations, potentially leading to information disclosure or modification. Defenders should verify the plugin's configuration and restrict access to prevent exploitation.
- Authenticated attackers with administrator-level access can make web requests to arbitrary locations.
- The vulnerability can be used to query and modify information from internal services.
- The plugin's dom_get_type setting must be configured to 'wp_remote_post' for the vulnerability to be reachable.
- Verification of the plugin's configuration and restriction of administrator-level access are necessary to prevent exploitation.
Technical summary
The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.0.5 via the 'page_url' parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Defensive priority
Administrators of WordPress installations using the Asset CleanUp: Page Speed Booster plugin should verify that the plugin's dom_get_type setting is not configured to 'wp_remote_post' and restrict administrator-level access to prevent exploitation.
Recommended defensive actions
- Verify that the plugin's dom_get_type setting is not configured to 'wp_remote_post'.
- Restrict administrator-level access to the WordPress installation.
- Monitor for suspicious web requests originating from the web application.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The vulnerability was reported by [email protected] and is described in the CVE Program record and the NVD vulnerability detail page. The reporter provided details on the plugin's configuration and the 'page_url' parameter vulnerability. Evidence is limited to public CVE Program and NVD records. Defenders should verify plugin configuration and restrict administrator-level access.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-12037 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-12037
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-12037 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-12037
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/wp-asset-clean-up/tags/1.4.0.3/classes/Admin/MainAdmin.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/wp-asset-clean-up/tags/1.4.0.4/classes/Admin/MainAdmin.php
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.