Unauthorized Access Vulnerability in 10Web Booster Plugin by WordPress
CVE-2026-14287
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 19 August 2026
Badges
What is CVE-2026-14287?
The 10Web Booster plugin for WordPress prior to version 2.33.5 is susceptible to an unauthorized access vulnerability. This issue arises due to inadequate validation of access tokens on an unauthenticated request handler. Additionally, the plugin fails to properly escape attacker-provided stylesheet content before it is rendered, which permits an unauthenticated adversary to inject markup that executes JavaScript in the browsers of anonymous users visiting affected pages. This can lead to the execution of malicious scripts, posing a significant risk to website visitors.
Affected Version(s)
10Web Booster 0 < 2.33.5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.