Vulnerability Description
Authenticated (admin+) Reflected Cross-Site Scripting (XSS) vulnerability in Gabe Livan's Asset CleanUp: Page Speed Booster plugin <= 1.3.8.4 at WordPress.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Asset Cleanup\ | Page Speed Booster Project | < 1.3.8.5, asset_cleanup\ |
Related Weaknesses (CWE)
References
- https://patchstack.com/database/vulnerability/wp-asset-clean-up/wordpress-asset-Third Party Advisory
- https://wordpress.org/plugins/wp-asset-clean-up/#developersProductThird Party Advisory
- https://patchstack.com/database/vulnerability/wp-asset-clean-up/wordpress-asset-Third Party Advisory
- https://wordpress.org/plugins/wp-asset-clean-up/#developersProductThird Party Advisory
FAQ
What is CVE-2021-36899?
CVE-2021-36899 is a vulnerability with a CVSS score of 4.8 (MEDIUM). Authenticated (admin+) Reflected Cross-Site Scripting (XSS) vulnerability in Gabe Livan's Asset CleanUp: Page Speed Booster plugin <= 1.3.8.4 at WordPress.
How severe is CVE-2021-36899?
CVE-2021-36899 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-36899?
Check the references section above for vendor advisories and patch information. Affected products include: Asset Cleanup\ Page Speed Booster Project.