Async JavaScript

Async JavaScript has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2020 and 2021; all 2 are fixed as of September 2026. Their average CVSS score is 6.0, and the most serious one scores 6.4 out of 10.

The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).

Every one of the 2 issues recorded for Async JavaScript has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. Async JavaScript is installed on roughly 70,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.2.11.

Strategic Overview

Avg CVSSMedium
6.0/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all Async JavaScript vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.4CVE-2020-36854

Async JavaScript <= 2.19.07.14 - Authenticated (Subscriber+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

2 records
Plugin Profile
Latestv2.21.08.31

Async JavaScript

David Clough

Author

David Clough

4.7(102)
94/100
Last Updated
2023-06-22 (3y ago)
Active Installs
70,000+
Downloads
2,061,432
Requires WP
4.6+
Requires PHP
0+
Tested up to
WP 6.2.11
Created
2014-12-11 (12y ago)

Eliminate Render-blocking Javascript in above-the-fold content with Async Javascript. Render-blocking Javascript prevents above-the-fold content on your page from being rendered until the javascript has finished loading. This can impact on your page speed and ultimately your ranking within search engines. It can also impact your user’s experience. Async JavaScript gives you full control of which scripts to add an &#8216;async’ or &#8216;defer’ attribute to or to exclude to help increase the performance of your WordPress website.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C