Sceawere
Vulnerability Detail
CVE-2026-94121UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
10Web Booster Object Injection Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 3h ago
- Vendor
- 10Web
- Product
- 10Web Booster – Website speed optimization, Cache & Page Speed optimizer
- Attack Type
- CWE-502 Deserialization of Untrusted Data
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Contributor PHP Object Injection in 10Web Booster – Website speed optimization, Cache & Page Speed optimizer <= 2.33.6 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-09-30T13:17:24.497Z",
"pubdate": "2026-09-30T13:17:24.497Z",
"executiveSummary": "The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is susceptible to a PHP Object Injection vulnerability affecting all versions up to and including 2.33.6.\nThe vulnerability originates from the insecure deserialization of user-supplied input provided by authenticated users with contributor-level privileges or higher.\nSuccessful exploitation of this flaw allows an attacker to inject arbitrary PHP objects into the application scope. This can be leveraged to trigger unintended code execution paths, perform unauthorized file system operations, or execute arbitrary code depending on the presence of available 'gadget chains' within the site's environment.\nThe primary risk implication is a potential full site compromise, as Object Injection vulnerabilities often bypass standard input validation mechanisms.\nExploitation requires an attacker to possess valid credentials for at least a contributor-level account on the target WordPress installation.\nNo complex network conditions are required, as the vulnerability is reachable through standard HTTP requests handled by the plugin's internal request processing logic.\nOrganizations using this plugin are advised to prioritize updates or restrict access to administrative/contributor interfaces until a security patch is verified.",
"technicalDetails": "The vulnerability stems from the improper handling of serialized data passed via POST or GET parameters that are subsequently processed by the PHP unserialize() function without adequate validation or sanitization.\nIn the context of the 10Web Booster plugin, the vulnerable component utilizes unsanitized input derived from HTTP request parameters to reconstruct internal state objects. By crafting a malicious serialized payload, an attacker can instantiate arbitrary classes defined within the application or its bundled dependencies.\nThe attack flow proceeds as follows: First, the attacker identifies the specific endpoint or hook where user-supplied input is passed to the unserialize() function. Second, the attacker prepares a PHP object payload designed to leverage existing 'gadgets'—classes within the WordPress core, theme, or active plugins that implement magic methods such as __destruct(), __wakeup(), or __toString().\nUpon transmission of the malicious payload, the application deserializes the input, instantiating the attacker-supplied object. The magic methods are triggered automatically during the object's lifecycle. If the attacker targets a gadget that facilitates file deletion, arbitrary data writing, or secondary code execution via reflection, the security boundary is bypassed.\nThis vulnerability is classified as PHP Object Injection (CWE-502). It is particularly severe because the payload does not need to contain direct shellcode; instead, it manipulates the application's internal object state to perform operations that the developer did not intend. The impact is dictated by the available codebase; if an attacker can identify a gadget chain that leads to Remote Code Execution (RCE), they can achieve complete control over the WordPress environment, including access to the underlying database and server filesystem.\nThe issue persists across versions 2.33.6 and earlier. Because the exploitation relies on the authentication of at least a contributor-level user, the attack surface is limited to logged-in users, though it remains a significant risk for environments with untrusted or compromised author/contributor accounts. The vulnerability is typically triggered through an authenticated request to a WordPress admin-ajax.php or similar REST API endpoint utilized by the plugin for configuration or speed optimization tasks."
}