Impact
The 10Web Booster plugin routine that generates the shared secret required for its cloud connection performs no authentication or authorization checks, allowing any visitor to invoke the routine and receive the secret. In addition to disclosure, the same endpoint permits deletion of the secret, effectively blocking an administrator from establishing a legitimate cloud connection. Thus the vulnerability enables attackers to obtain sensitive credentials and to cause a denial of service for the cloud integration.
Affected Systems
WordPress sites that have the 10Web Booster plugin installed with a version earlier than 2.34.0 are affected. No specific sub‑versions are listed, so all releases below 2.34.0 are considered vulnerable.
Risk and Exploitability
The flaw can be exploited by simply sending an HTTP request to the vulnerable endpoint; no authentication, privileged account, or special network condition is required. The vulnerability is not listed in the CISA KEV catalog. Because the secret disclosure can lead to hijacked or spoofed cloud connections and the deletion action forces administrators to re‑configure or re‑establish a connection, the overall risk is considered moderate to high for environments that rely on this cloud feature.
OpenCVE Enrichment