DIRAS TAKE
Act urgently: this is a stored XSS that requires no login to inject and can persistently affect visitors; prioritize disabling the vulnerable feature and applying vendor guidance as soon as a fix is released.
What is CVE-2026-13354?
Unauthenticated attackers can inject persistent JavaScript into pages served by the Asset CleanUp: Page Speed Booster WordPress plugin, enabling script execution in visitors' browsers (CVE-2026-13354). The flaw affects versions 1.4.0.5 and earlier on the 1.x branch and is exploitable when the plugin option combine_loaded_css is enabled; an attacker does not need an account, and injected scripts run whenever a user views an affected page. The weakness is classified as CWE-79 (Cross-site Scripting).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Which versions of gabelivan Asset CleanUp: Page Speed Booster are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 1.x | 1.4.0.5 and earlier |
Is CVE-2026-13354 being exploited?
There are no public reports of exploitation of CVE-2026-13354 as of 2026-09-30.
How to fix CVE-2026-13354
- Disable the plugin option combine_loaded_css immediately on affected sites to remove the exploit vector.
- Restrict exposure: block or limit access to vulnerable WordPress instances from the public internet until a fix is available.
- Monitor logs and web traffic for unusual script injections or unexpected POSTs to comment endpoints and remove any malicious content found.
- Follow the plugin vendor's guidance and install an official update as soon as the vendor releases a fixed version.
Frequently asked questions
Is CVE-2026-13354 being actively exploited?
There are no public reports of active exploitation of CVE-2026-13354 as of 2026-09-30; it is not listed in CISA's KEV catalog and no public exploit code is known.
Which Asset CleanUp: Page Speed Booster versions are affected by CVE-2026-13354?
Versions 1.4.0.5 and earlier on the 1.x branch of Asset CleanUp: Page Speed Booster are affected.
Is there a patch for CVE-2026-13354?
As of 2026-09-30 there is no fixed version listed; apply the vendor's guidance and the mitigations above and install a vendor patch when it becomes available.
Does CVE-2026-13354 require authentication?
No — the vulnerability can be triggered by unauthenticated attackers, but it is only exploitable when the plugin setting combine_loaded_css is enabled and an injected page is viewed by a user.
References
- nvd.nist.gov/vuln/detail/CVE-2026-13354
- cve.org/CVERecord?id=CVE-2026-13354
- wordfence.com/threat-intel/vulnerabilities/id/4cc8ec2b-f203-4c7c-8720-043f8634a447?source=cve
- plugins.trac.wordpress.org/browser/wp-asset-clean-up/tags/1.4.0.4/classes/OptimiseAssets/OptimizeCss.php#L579
- plugins.trac.wordpress.org/browser/wp-asset-clean-up/tags/1.4.0.4/classes/OptimiseAssets/OptimizeJs.php#L824
- plugins.trac.wordpress.org/browser/wp-asset-clean-up/tags/1.4.0.3/classes/OptimiseAssets/OptimizeCss.php#L579
- plugins.trac.wordpress.org/browser/wp-asset-clean-up/tags/1.4.0.3/classes/OptimiseAssets/OptimizeJs.php#L824
- research.cleantalk.org/cve-2026-13354
- plugins.trac.wordpress.org/changeset?reponame=&old=3699024%40wp-asset-clean-up&new=3699024%40wp-asset-clean-up
- All gabelivan CVEs on CVE Radar
- CVEs published in September 2026