Description
The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' parameter in all versions up to, and including, 2.34.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable because a comment author Name value containing ' src=' and an event-handler payload contains no HTML tags or quote characters, allowing it to survive WordPress core's sanitize_text_field and land verbatim inside the alt attribute, where the plugin's own str_replace subsequently injects the single quote that breaks out of the attribute context.
Published: 2026-10-10
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting (XSS)
Action: Patch Immediately
AI Analysis

Impact

The 10Web Booster plugin accepts a comment author name that is stored and later rendered without proper escaping. An attacker can inject a payload containing a script attribute, allowing arbitrary JavaScript to be executed on any page that displays the comment.

Affected Systems

All installations of the 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress through version 2.34.8 are affected. The flaw resides in the author field handling within OptimizerImages.php and the main plugin file, enabling attackers to inject code via the comment author input.

Risk and Exploitability

The CVSS score of 7.2 places the issue in the high‑severity range, and because the vulnerability is not tied to any authentication, it is easily exploitable. Although no EPSS score is reported, the lack of an authentication requirement gives the attacker a broad attack surface. The flaw is not listed in CISA’s KEV catalog, indicating that no widely known exploits have been documented yet, but the stored nature of the attack means that any user visiting a page with the injected comment will execute the malicious payload.

Generated by OpenCVE AI on October 10, 2026 at 09:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest plugin release (2.34.10) or newer, which removes the vulnerable author handling.
  • If an upgrade is not feasible immediately, remove the comment author field from the comment form or sanitize it by stripping disallowed tags before storage.
  • Deploy a site‑wide Content Security Policy that blocks inline scripts to mitigate the impact of potential unpatched XSS.

Generated by OpenCVE AI on October 10, 2026 at 09:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 07:00:00 +0000

Type Values Removed Values Added
Description The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' parameter in all versions up to, and including, 2.34.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable because a comment author Name value containing ' src=' and an event-handler payload contains no HTML tags or quote characters, allowing it to survive WordPress core's sanitize_text_field and land verbatim inside the alt attribute, where the plugin's own str_replace subsequently injects the single quote that breaks out of the attribute context.
Title 10Web Booster <= 2.34.8 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T06:40:15.105Z

Reserved: 2026-10-08T18:02:59.202Z

Link: CVE-2026-107742

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T07:16:40.843

Modified: 2026-10-10T07:16:40.843

Link: CVE-2026-107742

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T09:30:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')