{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aassetcleanuppage_speed_boosterwordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:assetcleanup:page_speed_booster:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-13354"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Asset CleanUp: Page Speed Booster (\u003c= 1.4.0.5)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Asset CleanUp: Page Speed Booster plugin for WordPress, specifically in versions 1.4.0.5 and earlier, contains a critical stored cross-site scripting (XSS) vulnerability, tracked as CVE-2026-13354. The vulnerability exists due to insufficient sanitization and output escaping when processing comment content. An unauthenticated attacker can leverage this flaw to inject arbitrary malicious web scripts into pages. These scripts are subsequently executed in the browser of any user who accesses the compromised page, potentially leading to unauthorized actions, session hijacking, or redirection. Successful exploitation is contingent on the site having the 'combine_loaded_css' configuration setting enabled. Given the nature of the vulnerability, it presents a high risk for sites that allow user comments and utilize this specific performance-enhancing plugin configuration.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of victim browsers. This can lead to the theft of session cookies, administrative account takeover, or redirection of users to malicious third-party websites. The vulnerability impacts all WordPress installations using the vulnerable plugin version with the specific CSS combination feature active.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the following actions to mitigate risk associated with CVE-2026-13354:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the 'Asset CleanUp: Page Speed Booster' plugin to a version released after 1.4.0.5 immediately.\u003c/li\u003e\n\u003cli\u003eReview WordPress site configurations and temporarily disable the 'combine_loaded_css' setting if immediate patching is not possible.\u003c/li\u003e\n\u003cli\u003ePerform an audit of existing comments and site content for embedded script tags or suspicious attributes if the site has been exposed to the internet.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-19T04:08:54Z","date_published":"2026-09-19T04:08:54Z","id":"https://feed.craftedsignal.io/briefs/2026-09-asset-cleanup-xss/","summary":"Asset CleanUp: Page Speed Booster versions 1.4.0.5 and earlier are vulnerable to stored cross-site scripting due to insufficient input sanitization of comment content.","title":"Stored XSS in Asset CleanUp: Page Speed Booster WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-asset-cleanup-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:assetcleanup:page_speed_booster:*:*:*:*:*:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}