Skip to content
Threat Feed
high advisory

Stored XSS in 10Web Booster WordPress Plugin (CVE-2026-107742)

The 10Web Booster WordPress plugin is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) via the author parameter in versions up to 2.34.8.

CVE search metadata

CVE search record: CVE-2026-107742. Severity: high. CVSS: 7.2. KEV: no. Product: 10Web Booster – Website speed optimization, Cache & Page Speed optimizer (<= 2.34.8). Brief: Stored XSS in 10Web Booster WordPress Plugin (CVE-2026-107742). Brief link: https://feed.craftedsignal.io/briefs/2026-10-10-cve-2026-107742/

The 10Web Booster - Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is affected by a critical Stored Cross-Site Scripting (XSS) vulnerability, tracked as CVE-2026-107742. This flaw exists in all versions up to and including 2.34.8. It stems from insufficient input sanitization and output escaping within the 'author' parameter used in comment processing. Unauthenticated attackers can inject malicious JavaScript payloads that bypass WordPress core's 'sanitize_text_field' function. The payload is successfully stored when it arrives verbatim within an 'alt' attribute, at which point the plugin's internal 'str_replace' function injects a single quote that breaks the attribute context, enabling the execution of arbitrary scripts in the browsers of users who view the affected pages. This vulnerability could lead to session hijacking, site defacement, or administrative account takeover if an administrator views the injected comment.

Impact

Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of an end-user's session. This poses a significant risk to site administrators, as it could facilitate the theft of session cookies, perform unauthorized actions on behalf of the administrator, or redirect users to malicious sites, potentially leading to a full site compromise.

Recommendation

Prioritized actions for security and IT teams to mitigate CVE-2026-107742:

  • Update the 10Web Booster plugin to the latest available version (beyond 2.34.8) immediately.
  • Audit WordPress comment sections for anomalous entries containing suspicious attributes or event handlers (e.g., 'onmouseover', 'onerror').
  • Deploy a Web Application Firewall (WAF) rule to inspect and block incoming HTTP POST requests containing common XSS vectors (e.g., event handlers or attribute breakout attempts) directed at WordPress comment submission endpoints.

Immediate actions

Upgrade 10Web Booster plugin to version > 2.34.8

IT Operations 24h

Mitigations

Patch 10Web Booster plugin

immediate IT Operations

CVE-2026-107742

Detection coverage 1

Detect CVE-2026-107742 - WordPress Stored XSS Attempt

high

Detects exploitation attempts against WordPress comment forms where the author name parameter contains attribute breakout characters or common XSS event handlers.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →