Impact
The 10Web Booster WordPress plugin before version 2.33.5 fails to verify an access token in an unauthenticated request handler and renders attacker‑supplied stylesheet content in the page head without escaping. This allows an unauthenticated attacker to store markup that executes as JavaScript in the browsers of anonymous visitors to any affected page, enabling cross‑site scripting attacks.
Affected Systems
All sites running the 10Web Booster plugin from an unknown vendor, version 2.33.4 and earlier. No specific operating system or platform restrictions are noted; the vulnerability exists solely within the WordPress plugin code.
Risk and Exploitability
The CVSS base score is 4.7, indicating low severity. The EPSS score of less than 1% suggests the likelihood of exploitation is low, and the vulnerability is not yet listed in the CISA KEV catalog. Attackers can trigger the vulnerability from any network location by submitting crafted data to the critical‑CSS token endpoint; no authentication or elevated privileges are required, so the attack vector is unauthenticated. The impact is limited to the browsers of visitors who view the affected page.
OpenCVE Enrichment