PT-2026-97708 · WordPress · 10Web Booster
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
10Web Booster versions prior to 2.34.0
Description
The plugin fails to restrict access to the routine responsible for issuing the shared secret used to authenticate cloud connections. This allows unauthenticated visitors to disclose the secret and delete it repeatedly, which prevents administrators from establishing a legitimate connection.
Recommendations
Update 10Web Booster to version 2.34.0 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
10Web Booster