10Web Booster – Website speed optimization, Cache & Page Speed optimizer(一款用于 WordPress 的网站速度优化、缓存与页面速度优化插件)在所有版本中(包括最高至 2.34.8 版本)均存在存储型跨站脚本(Stored Cross-Site Scripting, XSS)漏洞,原因是其对输入清理和输出转义处理不足。这使得未经身份验证的攻击者能够在网页中注入任意 Web 脚本,当用户访问被注入的页面时,这些脚本将会被执行。 该漏洞之所以可利
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| 10web | 10Web Booster – Website speed optimization, Cache & Page Speed optimizer | ≤ 2.34.8 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| 10web | 10Web Booster – Website speed optimization, Cache & Page Speed optimizer | 0 ~ 2.34.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105885 | 8.8 HIGH | WordPress Slider by 10Web plugin <= 1.2.62 - PHP Object Injection vulnerability |
| CVE-2026-42711 | 7.1 HIGH | WordPress Slider by 10Web plugin <= 1.2.63 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-42715 | 7.1 HIGH | WordPress Photo Gallery by 10Web plugin <= 1.8.47 - Cross Site Scripting (XSS) vulnerabili |
| CVE-2026-103998 | 6.1 MEDIUM | Form Maker by 10Web <= 1.15.48 - Reflected Cross-Site Scripting via 'inputs' Parameter Arr |
No comments yet