Async JavaScript
Async JavaScript has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2020 and 2021; all 2 are fixed as of September 2026. Their average CVSS score is 6.0, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).
Every one of the 2 issues recorded for Async JavaScript has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Async JavaScript is installed on roughly 70,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.2.11.
CVE-2020-36854Async JavaScript <= 2.19.07.14 - Authenticated (Subscriber+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records
Async JavaScript
Author
David Clough
Eliminate Render-blocking Javascript in above-the-fold content with Async Javascript. Render-blocking Javascript prevents above-the-fold content on your page from being rendered until the javascript has finished loading. This can impact on your page speed and ultimately your ranking within search engines. It can also impact your user’s experience. Async JavaScript gives you full control of which scripts to add an ‘async’ or ‘defer’ attribute to or to exclude to help increase the performance of your WordPress website.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C