PT-2022-10596 · WordPress · Asset Cleanup: Page Speed Booster

Nguyen Van

+1

·

Published

2022-10-11

·

Updated

2022-10-11

·

CVE-2021-36899

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Asset CleanUp: Page Speed Booster plugin versions <= 1.3.8.4
Description The issue is related to an Authenticated Reflected Cross-Site Scripting (XSS) vulnerability. This type of vulnerability allows an attacker to inject malicious scripts into a website, potentially leading to unauthorized actions. The vulnerability requires authentication with admin or higher privileges, indicating it needs access to sensitive areas of the website.
Recommendations For Asset CleanUp: Page Speed Booster plugin versions <= 1.3.8.4, update to a version higher than 1.3.8.4 to resolve the issue.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-36899

Affected Products

Asset Cleanup: Page Speed Booster