PT-2026-78277 · WordPress · 10Web Booster
CVSS v3.1
4.7
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
10Web Booster versions prior to 2.33.5
Description
An unauthenticated request handler fails to correctly validate access tokens and does not escape stylesheet content provided by users before rendering it into the page head. This allows an unauthenticated attacker to store markup that executes as JavaScript in the browsers of anonymous visitors to an affected page, leading to a stored cross-site scripting (XSS) condition.
Recommendations
Update 10Web Booster to version 2.33.5 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
10Web Booster