CVE-2026-13354: stored cross-site scripting in gabelivan Asset CleanUp: Page Speed Booster

Unauthenticated attackers can inject persistent JavaScript into pages served by the Asset CleanUp: Page Speed Booster WordPress plugin, enabling script execution in visitors' browsers (CVE-2026-13354). The flaw affects versions 1.4.0.5 and earlier on the 1.x branch and is exploitable when the plugin option combine_loaded_css is enabled; an attacker does not need an account, and injected scripts run whenever a user views an affected page.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
7.2HIGH
EPSS
0.00241
CWE
CWE-79
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Act urgently: this is a stored XSS that requires no login to inject and can persistently affect visitors; prioritize disabling the vulnerable feature and applying vendor guidance as soon as a fix is released.

What is CVE-2026-13354?

Unauthenticated attackers can inject persistent JavaScript into pages served by the Asset CleanUp: Page Speed Booster WordPress plugin, enabling script execution in visitors' browsers (CVE-2026-13354). The flaw affects versions 1.4.0.5 and earlier on the 1.x branch and is exploitable when the plugin option combine_loaded_css is enabled; an attacker does not need an account, and injected scripts run whenever a user views an affected page. The weakness is classified as CWE-79 (Cross-site Scripting).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Which versions of gabelivan Asset CleanUp: Page Speed Booster are affected?

BRANCHAFFECTEDFIXED
1.x1.4.0.5 and earlier

Is CVE-2026-13354 being exploited?

There are no public reports of exploitation of CVE-2026-13354 as of 2026-09-30.

How to fix CVE-2026-13354

  1. Disable the plugin option combine_loaded_css immediately on affected sites to remove the exploit vector.
  2. Restrict exposure: block or limit access to vulnerable WordPress instances from the public internet until a fix is available.
  3. Monitor logs and web traffic for unusual script injections or unexpected POSTs to comment endpoints and remove any malicious content found.
  4. Follow the plugin vendor's guidance and install an official update as soon as the vendor releases a fixed version.

Frequently asked questions

Is CVE-2026-13354 being actively exploited?

There are no public reports of active exploitation of CVE-2026-13354 as of 2026-09-30; it is not listed in CISA's KEV catalog and no public exploit code is known.

Which Asset CleanUp: Page Speed Booster versions are affected by CVE-2026-13354?

Versions 1.4.0.5 and earlier on the 1.x branch of Asset CleanUp: Page Speed Booster are affected.

Is there a patch for CVE-2026-13354?

As of 2026-09-30 there is no fixed version listed; apply the vendor's guidance and the mitigations above and install a vendor patch when it becomes available.

Does CVE-2026-13354 require authentication?

No — the vulnerability can be triggered by unauthenticated attackers, but it is only exploitable when the plugin setting combine_loaded_css is enabled and an injected page is viewed by a user.

References