{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3a10webbooster_website_speed_optimization_cache_page_speed_optimizer/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:10web:booster_website_speed_optimization_cache_page_speed_optimizer:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-107742"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["10Web Booster – Website speed optimization, Cache \u0026 Page Speed optimizer (\u003c= 2.34.8)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["10Web"],"content_html":"\u003cp\u003eThe 10Web Booster - Website speed optimization, Cache \u0026amp; Page Speed optimizer plugin for WordPress is affected by a critical Stored Cross-Site Scripting (XSS) vulnerability, tracked as CVE-2026-107742. This flaw exists in all versions up to and including 2.34.8. It stems from insufficient input sanitization and output escaping within the 'author' parameter used in comment processing. Unauthenticated attackers can inject malicious JavaScript payloads that bypass WordPress core's 'sanitize_text_field' function. The payload is successfully stored when it arrives verbatim within an 'alt' attribute, at which point the plugin's internal 'str_replace' function injects a single quote that breaks the attribute context, enabling the execution of arbitrary scripts in the browsers of users who view the affected pages. This vulnerability could lead to session hijacking, site defacement, or administrative account takeover if an administrator views the injected comment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of an end-user's session. This poses a significant risk to site administrators, as it could facilitate the theft of session cookies, perform unauthorized actions on behalf of the administrator, or redirect users to malicious sites, potentially leading to a full site compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and IT teams to mitigate CVE-2026-107742:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the 10Web Booster plugin to the latest available version (beyond 2.34.8) immediately.\u003c/li\u003e\n\u003cli\u003eAudit WordPress comment sections for anomalous entries containing suspicious attributes or event handlers (e.g., 'onmouseover', 'onerror').\u003c/li\u003e\n\u003cli\u003eDeploy a Web Application Firewall (WAF) rule to inspect and block incoming HTTP POST requests containing common XSS vectors (e.g., event handlers or attribute breakout attempts) directed at WordPress comment submission endpoints.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-10T07:52:23Z","date_published":"2026-10-10T07:52:23Z","id":"https://feed.craftedsignal.io/briefs/2026-10-10-cve-2026-107742/","summary":"The 10Web Booster WordPress plugin is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) via the author parameter in versions up to 2.34.8.","title":"Stored XSS in 10Web Booster WordPress Plugin (CVE-2026-107742)","url":"https://feed.craftedsignal.io/briefs/2026-10-10-cve-2026-107742/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:10web:booster_website_speed_optimization_cache_page_speed_optimizer:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}