Impact
The 10Web Booster plugin accepts a comment author name that is stored and later rendered without proper escaping. An attacker can inject a payload containing a script attribute, allowing arbitrary JavaScript to be executed on any page that displays the comment.
Affected Systems
All installations of the 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress through version 2.34.8 are affected. The flaw resides in the author field handling within OptimizerImages.php and the main plugin file, enabling attackers to inject code via the comment author input.
Risk and Exploitability
The CVSS score of 7.2 places the issue in the high‑severity range, and because the vulnerability is not tied to any authentication, it is easily exploitable. Although no EPSS score is reported, the lack of an authentication requirement gives the attacker a broad attack surface. The flaw is not listed in CISA’s KEV catalog, indicating that no widely known exploits have been documented yet, but the stored nature of the attack means that any user visiting a page with the injected comment will execute the malicious payload.
OpenCVE Enrichment