Description
Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.
Published: 2026-08-24
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Boost plugin for WordPress contains an unauthenticated cross‑site scripting flaw that enables attackers to inject arbitrary JavaScript into the site. This flaw can result in defacement, phishing, or the theft of user session data if a user views a page affected by the injected code. The weakness is a classic injection vulnerability and is identified as CWE‑79.

Affected Systems

Affected products include the WordPress Boost plugin from PixelYourSite Professional. All releases up to and including version 2.0.4 are vulnerable, as the CVE indicates that Boost versions 2.0.4 or earlier contain the flaw.

Risk and Exploitability

The CVSS score of 7.1 reflects a high risk level, and the vulnerability is not listed in CISA’s KEV catalog. EPSS data is not available, but the unauthenticated nature of the flaw means that any external user can trigger the injection, making it likely to be exploited if the plugin remains in use. Because no official workaround exists, the only effective remediation is to update or remove the vulnerable plugin.

Generated by OpenCVE AI on August 24, 2026 at 22:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Boost plugin to the latest available version, which includes the XSS fix.
  • If an update cannot be applied, deactivate or delete the Boost plugin from the WordPress installation.
  • Clear cached content on the site to ensure no old, vulnerable code remains.

Generated by OpenCVE AI on August 24, 2026 at 22:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.
Title WordPress Boost plugin <= 2.0.4 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-24T21:31:26.430Z

Reserved: 2026-03-12T11:12:38.877Z

Link: CVE-2026-32556

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-24T22:16:51.773

Modified: 2026-08-24T22:16:51.773

Link: CVE-2026-32556

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T22:30:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')