CVE-2026-45212
Description
Missing Authorization vulnerability in Gabe Livan Asset CleanUp: Page Speed Booster wp-asset-clean-up allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Asset CleanUp: Page Speed Booster: from n/a through <= 1.4.0.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A missing authorization vulnerability in Asset CleanUp: Page Speed Booster allows unprivileged users to execute higher privileged actions; update to 1.4.0.4.
The Asset CleanUp: Page Speed Booster plugin for WordPress (versions up to 1.4.0.3) suffers from a missing authorization vulnerability. This means that certain functions lack proper access control checks, allowing unprivileged users to perform actions that should require higher privileges [1].
Attackers exploiting this issue do not need authentication or can leverage low-privileged accounts to trigger privileged operations. This type of broken access control is commonly targeted in mass-exploit campaigns, affecting thousands of sites regardless of size [1].
The impact includes the ability to execute unauthorized actions within the plugin, potentially leading to data manipulation or site compromise. The CVSS score of 5.3 (Medium) reflects the moderate severity due to the low complexity and network attack vector [1].
As a mitigation, users must update the plugin to version 1.4.0.4, which contains the fix. Those unable to update should seek assistance from their hosting provider. The vulnerability is considered low risk and unlikely to be exploited, but immediate patching is recommended [1].
AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3<=1.4.0.3+ 1 more
- (no CPE)range: <=1.4.0.3
- (no CPE)range: <=1.4.0.3
- Range: <=1.4.0.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.