Sceawere
Vulnerability Detail
CVE-2026-107742UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
10Web Booster Stored XSS Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 3h ago
- Vendor
- 10web
- Product
- 10Web Booster – Website speed optimization, Cache & Page Speed optimizer
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' parameter in all versions up to, and including, 2.34.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable because a comment author Name value containing ' src=' and an event-handler payload contains no HTML tags or quote characters, allowing it to survive WordPress core's sanitize_text_field and land verbatim inside the alt attribute, where the plugin's own str_replace subsequently injects the single quote that breaks out of the attribute context.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-10-10T07:16:40.843Z",
"pubdate": "2026-10-10T07:16:40.843Z",
"executiveSummary": "The 10Web Booster plugin for WordPress, in versions up to and including 2.34.8, contains a critical Stored Cross-Site Scripting (XSS) vulnerability.\nThis vulnerability stems from inadequate sanitization and output escaping of the 'author' parameter when processing comment data.\nUnauthenticated attackers can inject arbitrary JavaScript payloads into comment author names, which are subsequently executed in the context of a victim's browser session when they view the affected page.\nThe risk is severe as it allows for unauthorized script execution, potential session hijacking, administrative action spoofing, and unauthorized redirection or content modification.\nSuccessful exploitation requires no prior authentication or administrative privileges, as the attack vector leverages standard comment submission functionality.\nThe vulnerability occurs because the plugin fails to properly handle malicious inputs that bypass WordPress core sanitization functions, subsequently introducing quotes into the DOM that break out of the intended HTML attribute context.",
"technicalDetails": "The vulnerability resides in the way 10Web Booster handles the 'author' parameter for comment inputs. The root cause is a combination of insufficient input validation and an insecure secondary processing step performed by the plugin.\nAlthough WordPress core utilizes the sanitize_text_field function, this protection is insufficient against payloads specifically crafted to bypass filter constraints. An attacker can supply a malicious string containing ' src=' and event-handler attributes (e.g., onerror, onload) that are devoid of restricted HTML tags or explicit quote characters.\nBecause the payload contains no quote characters, it successfully passes through WordPress core sanitization routines. Once processed, the input is stored in the database and subsequently rendered within an 'alt' attribute of an HTML element generated by the plugin.\nThe exploit sequence triggers when the plugin performs a specific str_replace operation. This function erroneously injects a single quote into the payload while it is already situated within the 'alt' attribute context. This injection effectively closes the attribute prematurely, allowing the subsequent event-handler (such as 'onerror=alert(1)') to be treated as a valid HTML attribute within the tag.\nThe attack flow follows these steps: 1) The attacker submits a comment with a specially crafted 'author' name field containing non-quoted malicious JavaScript event handlers. 2) The input bypasses sanitize_text_field because it lacks forbidden characters. 3) The malicious string is saved into the database. 4) The plugin retrieves this data and renders it inside an HTML 'alt' attribute. 5) A plugin-side str_replace function introduces a single quote, terminating the 'alt' attribute and converting the malicious string into an active executable handler within the DOM.\nThe execution occurs whenever an unsuspecting user, such as an administrator, views a page containing the injected comment. The browser interprets the injected event handler, leading to XSS. This grants the attacker the ability to execute arbitrary code within the victim's session, leading to potential account takeover, theft of authentication cookies, or administrative actions performed without authorization."
}