TenWeb Speed Optimizer <= 2.33.4 - Unauthenticated Stored Cross-Site Scripting
high
The TenWeb Speed Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.33.4. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whene...
- CVSS:
- 7.2
- Affected:
- up to 2.33.4
- Fixed in:
- 2.33.5
- Disclosed:
- Aug 17, 2026
CVE-2026-14287 on NVD →
10Web Booster <= 2.32.7 - Authenticated (Subscriber+) Arbitrary Folder Deletion via two_clear_page_cache
critical
The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is vulnerable to arbitrary folder deletion due to insufficient file path validation in the get_cache_dir_for_page_from_url() function in all versions up to, and including, 2.32.7. This makes it possible for authenticated a...
- CVSS:
- 9.6
- Affected:
- up to 2.32.7
- Fixed in:
- 2.32.11
- Disclosed:
- Dec 5, 2025
CVE-2025-13377 on NVD →
10Web Booster <= 2.24.14 - Unauthenticated Arbitrary Option Deletion
medium
The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is vulnerable to unauthorized loss of data due to insufficient validation on the option value being supplied to the two_init_flow_score and the two_init_flow_score functions hooked via nopriv AJAX in all versions up to, an...
- CVSS:
- 6.5
- Affected:
- up to 2.24.14
- Fixed in:
- 2.24.18
- Disclosed:
- Oct 29, 2023
CVE-2023-5559 on NVD →
10Web Booster – Website speed optimization, Cache & Page Speed optimizer <= 2.13.44 - Missing Authorization in Settings Import to Stored Cross-Site Scripting
high
The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check within the settings import functionality in versions up to, and including, 2.13.44. This makes it possible for unauthenticated attackers...
- CVSS:
- 7.2
- Affected:
- up to 2.13.44
- Fixed in:
- 2.13.45
- Disclosed:
- Feb 21, 2023
10Web Booster – Website speed optimization, Cache & Page Speed optimizer <= 2.12.23 - Unauthenticated SQL Injection
high
The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is vulnerable to SQL Injection via the filtered_ids parameter in versions up to, and including, 2.12.23 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL que...
- CVSS:
- 8.8
- Affected:
- up to 2.12.22
- Fixed in:
- 2.12.23
- Disclosed:
- Jan 25, 2023
10Web Booster – Website speed optimization, Cache & Page Speed optimizer <= 2.8.34 - Missing Authorization to Plugin Deactivation
medium
The 10Web Booster plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the two_deactivate_plugin function in versions up to, and including, 2.8.34. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to deactivate incompatible plugi...
- CVSS:
- 5.4
- Affected:
- up to 2.8.34
- Fixed in:
- 2.8.35
- Disclosed:
- Nov 19, 2022
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database