Cross Site Scripting Vulnerability in Boost Plugin by WordPress
CVE-2026-32556
7.1HIGH
What is CVE-2026-32556?
The Boost Plugin for WordPress contains an unauthenticated Cross Site Scripting (XSS) vulnerability in versions 2.0.4 and earlier. This security flaw allows attackers to inject malicious scripts into web pages viewed by users, potentially leading to data theft, session hijacking, or other malicious activities. Website administrators are advised to update to the latest version of the Boost Plugin to mitigate this risk.
Affected Version(s)
Boost <= 2.0.4