Stored Cross-Site Scripting in 10Web Booster Plugin for WordPress
CVE-2026-107742

7.2HIGH

What is CVE-2026-107742?

The 10Web Booster plugin for WordPress suffers from a Stored Cross-Site Scripting vulnerability that can be exploited through the 'author' parameter. This vulnerability arises from inadequate input sanitization and output escaping, enabling unauthenticated attackers to inject malicious scripts that execute when users access compromised pages. By using specific payloads containing ' src=' and event handler attributes, attackers can bypass the sanitization routines in WordPress and gain the ability to alter the content of the affected website.

Affected Version(s)

10Web Booster – Website speed optimization, Cache & Page Speed optimizer 0 <= 2.34.8

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

daroo
.