CVE-2026-12037 Overview
The Asset CleanUp: Page Speed Booster plugin for WordPress contains a Server-Side Request Forgery (SSRF) vulnerability affecting all versions up to and including 1.4.0.5. The flaw resides in the handling of the page_url parameter and allows authenticated attackers with administrator-level privileges to issue web requests to arbitrary destinations from the WordPress server. Exploitation enables querying and modifying information exposed by internal services that would otherwise be unreachable from the public internet. The vulnerability is only reachable when an administrator has configured the plugin's dom_get_type setting to wp_remote_post. This issue is tracked under CWE-918.
Critical Impact
Authenticated administrators can pivot through the WordPress server to probe or interact with internal network services, including cloud metadata endpoints, databases, and admin panels not exposed externally.
Affected Products
- Asset CleanUp: Page Speed Booster plugin for WordPress — all versions through 1.4.0.5
- Vulnerable code paths referenced in classes/Admin/MainAdmin.php at lines 315, 1067, and 1095
- Only exploitable when dom_get_type is set to wp_remote_post
Discovery Timeline
- 2026-09-25 - CVE CVE-2026-12037 published to NVD
- 2026-09-25 - Last updated in NVD database
Technical Details for CVE-2026-12037
Vulnerability Analysis
The Asset CleanUp plugin exposes administrative functionality that accepts a user-controlled page_url parameter and passes it into an outbound HTTP request routine. When the plugin's dom_get_type option is set to wp_remote_post, the plugin invokes wp_remote_post() against the attacker-supplied URL without sufficient validation of the target host. The outbound request originates from the WordPress server, bypassing network perimeter controls that normally shield internal services.
Attackers with administrator access can direct the request at loopback addresses, RFC1918 ranges, link-local metadata endpoints such as 169.254.169.254, or internal management interfaces. Because the plugin issues POST requests, attackers can also submit arbitrary request bodies to internal APIs, enabling state-changing operations rather than read-only reconnaissance.
Root Cause
The root cause is missing destination validation on the page_url input before it reaches the HTTP client. The plugin does not restrict the URL scheme, resolve and validate the destination IP against a deny-list of internal ranges, or require that the target match the WordPress site's own origin. See the WordPress Plugin Code Reference for the vulnerable code path.
Attack Vector
Exploitation requires authenticated administrator access and a target configuration where dom_get_type equals wp_remote_post. An attacker meeting both preconditions sends a crafted request to the vulnerable admin endpoint supplying page_url with an internal target. The WordPress server then issues the outbound request on the attacker's behalf and may return response data to the admin interface. Details are documented in the Wordfence Vulnerability Report.
Detection Methods for CVE-2026-12037
Indicators of Compromise
- Outbound HTTP requests from the WordPress server to RFC1918, loopback, or cloud metadata addresses such as 169.254.169.254.
- Web server access logs showing admin-authenticated requests containing the page_url parameter with non-site URLs.
- Unexpected POST requests originating from the WordPress host targeting internal management ports.
Detection Strategies
- Inspect PHP outbound HTTP traffic for destinations that resolve to private address space or non-public hostnames.
- Correlate WordPress audit logs with egress firewall logs to identify admin-triggered requests to unusual destinations.
- Alert on plugin configuration changes that set dom_get_type to wp_remote_post.
Monitoring Recommendations
- Enable WordPress activity logging to capture administrator interactions with the Asset CleanUp settings page.
- Monitor the plugin version across managed sites and flag any instance running 1.4.0.5 or earlier.
- Enforce egress filtering on the WordPress host and alert on blocked requests to internal CIDR ranges.
How to Mitigate CVE-2026-12037
Immediate Actions Required
- Update the Asset CleanUp: Page Speed Booster plugin to the version released after 1.4.0.5 as published in the WordPress Change Set.
- Audit administrator accounts and rotate credentials for any account that may have been compromised.
- Review the plugin's dom_get_type configuration and revert to a non-wp_remote_post value if the setting is not required.
Patch Information
The vendor addressed the SSRF in the release following 1.4.0.5. Site operators should apply the update through the WordPress plugin dashboard or by deploying the fixed package from the official repository. Confirm the installed version in wp-admin after the update completes.
Workarounds
- Restrict administrator access using multi-factor authentication and IP allow-listing on wp-admin.
- Configure the plugin so dom_get_type is not set to wp_remote_post until the patch is applied.
- Apply egress network ACLs on the WordPress host to block outbound traffic to internal address ranges and the cloud metadata service.
# Example egress restriction using iptables to block requests to
# the AWS/GCP/Azure metadata endpoint from the WordPress host
iptables -A OUTPUT -d 169.254.169.254 -j DROP
iptables -A OUTPUT -d 10.0.0.0/8 -p tcp --dport 80 -j DROP
iptables -A OUTPUT -d 10.0.0.0/8 -p tcp --dport 443 -j DROP
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.