plugin

Tenweb Speed Optimizer Vulnerabilities

6 known security issues reported for the Tenweb Speed Optimizer WordPress plugin. Most recent disclosed Aug 17, 2026.

1 critical 3 high 2 medium

Running Tenweb Speed Optimizer on your site? Check whether your installed version is affected.

Scan your site free

TenWeb Speed Optimizer <= 2.33.4 - Unauthenticated Stored Cross-Site Scripting

high

The TenWeb Speed Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.33.4. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whene...

CVSS:
7.2
Affected:
up to 2.33.4
Fixed in:
2.33.5
Disclosed:
Aug 17, 2026

CVE-2026-14287 on NVD →

10Web Booster <= 2.32.7 - Authenticated (Subscriber+) Arbitrary Folder Deletion via two_clear_page_cache

critical

The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is vulnerable to arbitrary folder deletion due to insufficient file path validation in the get_cache_dir_for_page_from_url() function in all versions up to, and including, 2.32.7. This makes it possible for authenticated a...

CVSS:
9.6
Affected:
up to 2.32.7
Fixed in:
2.32.11
Disclosed:
Dec 5, 2025

CVE-2025-13377 on NVD →

10Web Booster <= 2.24.14 - Unauthenticated Arbitrary Option Deletion

medium

The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is vulnerable to unauthorized loss of data due to insufficient validation on the option value being supplied to the two_init_flow_score and the two_init_flow_score functions hooked via nopriv AJAX in all versions up to, an...

CVSS:
6.5
Affected:
up to 2.24.14
Fixed in:
2.24.18
Disclosed:
Oct 29, 2023

CVE-2023-5559 on NVD →

10Web Booster – Website speed optimization, Cache & Page Speed optimizer <= 2.13.44 - Missing Authorization in Settings Import to Stored Cross-Site Scripting

high

The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check within the settings import functionality in versions up to, and including, 2.13.44. This makes it possible for unauthenticated attackers...

CVSS:
7.2
Affected:
up to 2.13.44
Fixed in:
2.13.45
Disclosed:
Feb 21, 2023

10Web Booster – Website speed optimization, Cache & Page Speed optimizer <= 2.12.23 - Unauthenticated SQL Injection

high

The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is vulnerable to SQL Injection via the filtered_ids parameter in versions up to, and including, 2.12.23 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL que...

CVSS:
8.8
Affected:
up to 2.12.22
Fixed in:
2.12.23
Disclosed:
Jan 25, 2023

10Web Booster – Website speed optimization, Cache & Page Speed optimizer <= 2.8.34 - Missing Authorization to Plugin Deactivation

medium

The 10Web Booster plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the two_deactivate_plugin function in versions up to, and including, 2.8.34. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to deactivate incompatible plugi...

CVSS:
5.4
Affected:
up to 2.8.34
Fixed in:
2.8.35
Disclosed:
Nov 19, 2022

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database