What the vulnerability does
01Description
Missing Authorization vulnerability in Gabe Livan Asset CleanUp: Page Speed Booster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Asset CleanUp: Page Speed Booster: from n/a through 1.3.9.3.
Explanation of Vulnerability in Simple Terms
02Summary
Asset CleanUp: Page Speed Booster versions up to 1.3.9.3 lack proper authorization checks, allowing authenticated users with low privileges to modify site data they should not access. An attacker with a basic user account can alter settings or content without proper permission validation. Update to a version newer than 1.3.9.3 to resolve this issue.
What an attacker can do
03Attacker Capabilities
Modify site data or settings without proper authorization as a low-privilege authenticated user.
Potential impact on your site
04Site Impact
Unauthorized changes to site configuration or content by low-privilege users; data integrity at risk.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege user account on the site (e.g., subscriber or contributor role).
Key dates
06Disclosure timeline
November 1, 2024
CVE published
April 28, 2026
Record updated