Stored Cross-Site Scripting in 10Web Booster Plugin for WordPress
CVE-2026-107742
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 October 2026
What is CVE-2026-107742?
The 10Web Booster plugin for WordPress suffers from a Stored Cross-Site Scripting vulnerability that can be exploited through the 'author' parameter. This vulnerability arises from inadequate input sanitization and output escaping, enabling unauthenticated attackers to inject malicious scripts that execute when users access compromised pages. By using specific payloads containing ' src=' and event handler attributes, attackers can bypass the sanitization routines in WordPress and gain the ability to alter the content of the affected website.
Affected Version(s)
10Web Booster β Website speed optimization, Cache & Page Speed optimizer 0 <= 2.34.8