Description
The 10Web Booster WordPress plugin before 2.34.0 does not restrict access to the routine which issues the shared secret that authenticates its cloud connection, disclosing that secret to unauthenticated visitors and letting them delete it repeatedly, preventing an administrator from completing a legitimate connection.
Published: 2026-09-24
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply patch
AI Analysis

Impact

The 10Web Booster plugin routine that generates the shared secret required for its cloud connection performs no authentication or authorization checks, allowing any visitor to invoke the routine and receive the secret. In addition to disclosure, the same endpoint permits deletion of the secret, effectively blocking an administrator from establishing a legitimate cloud connection. Thus the vulnerability enables attackers to obtain sensitive credentials and to cause a denial of service for the cloud integration.

Affected Systems

WordPress sites that have the 10Web Booster plugin installed with a version earlier than 2.34.0 are affected. No specific sub‑versions are listed, so all releases below 2.34.0 are considered vulnerable.

Risk and Exploitability

The flaw can be exploited by simply sending an HTTP request to the vulnerable endpoint; no authentication, privileged account, or special network condition is required. The vulnerability is not listed in the CISA KEV catalog. Because the secret disclosure can lead to hijacked or spoofed cloud connections and the deletion action forces administrators to re‑configure or re‑establish a connection, the overall risk is considered moderate to high for environments that rely on this cloud feature.

Generated by OpenCVE AI on September 24, 2026 at 13:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the 10Web Booster plugin to version 2.34.0 or later, which restricts access to the secret routine.
  • If an upgrade is not possible, disable or remove the Cloud Connection feature in the plugin to stop the routine from being exposed.
  • Apply a web application firewall rule to block unauthenticated requests to the secret routine endpoint, preventing further disclosure.

Generated by OpenCVE AI on September 24, 2026 at 13:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-285

Thu, 24 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 24 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-285

Thu, 24 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The 10Web Booster WordPress plugin before 2.34.0 does not restrict access to the routine which issues the shared secret that authenticates its cloud connection, disclosing that secret to unauthenticated visitors and letting them delete it repeatedly, preventing an administrator from completing a legitimate connection.
Title 10Web Booster < 2.34.0 - Unauthenticated Connection Secret Disclosure and Deletion
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-24T10:41:55.812Z

Reserved: 2026-08-28T07:51:23.756Z

Link: CVE-2026-82195

cve-icon Vulnrichment

Updated: 2026-09-24T10:35:39.747Z

cve-icon NVD

Status : Deferred

Published: 2026-09-24T06:17:01.540

Modified: 2026-09-24T14:42:02.707

Link: CVE-2026-82195

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T13:30:18Z

Weaknesses