<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Asset CleanUp: Page Speed Booster (&lt;= 1.4.0.5) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/asset-cleanup-page-speed-booster--1.4.0.5/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 19 Sep 2026 04:08:54 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/asset-cleanup-page-speed-booster--1.4.0.5/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored XSS in Asset CleanUp: Page Speed Booster WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-09-asset-cleanup-xss/</link><pubDate>Sat, 19 Sep 2026 04:08:54 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-asset-cleanup-xss/</guid><description>Asset CleanUp: Page Speed Booster versions 1.4.0.5 and earlier are vulnerable to stored cross-site scripting due to insufficient input sanitization of comment content.</description><content:encoded><![CDATA[<p>The Asset CleanUp: Page Speed Booster plugin for WordPress, specifically in versions 1.4.0.5 and earlier, contains a critical stored cross-site scripting (XSS) vulnerability, tracked as CVE-2026-13354. The vulnerability exists due to insufficient sanitization and output escaping when processing comment content. An unauthenticated attacker can leverage this flaw to inject arbitrary malicious web scripts into pages. These scripts are subsequently executed in the browser of any user who accesses the compromised page, potentially leading to unauthorized actions, session hijacking, or redirection. Successful exploitation is contingent on the site having the 'combine_loaded_css' configuration setting enabled. Given the nature of the vulnerability, it presents a high risk for sites that allow user comments and utilize this specific performance-enhancing plugin configuration.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of victim browsers. This can lead to the theft of session cookies, administrative account takeover, or redirection of users to malicious third-party websites. The vulnerability impacts all WordPress installations using the vulnerable plugin version with the specific CSS combination feature active.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the following actions to mitigate risk associated with CVE-2026-13354:</p>
<ul>
<li>Update the 'Asset CleanUp: Page Speed Booster' plugin to a version released after 1.4.0.5 immediately.</li>
<li>Review WordPress site configurations and temporarily disable the 'combine_loaded_css' setting if immediate patching is not possible.</li>
<li>Perform an audit of existing comments and site content for embedded script tags or suspicious attributes if the site has been exposed to the internet.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>