<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>10Web Booster – Website Speed Optimization, Cache &amp; Page Speed Optimizer (&lt;= 2.34.8) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/10web-booster--website-speed-optimization-cache--page-speed-optimizer--2.34.8/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 10 Oct 2026 07:52:23 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/10web-booster--website-speed-optimization-cache--page-speed-optimizer--2.34.8/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored XSS in 10Web Booster WordPress Plugin (CVE-2026-107742)</title><link>https://feed.craftedsignal.io/briefs/2026-10-10-cve-2026-107742/</link><pubDate>Sat, 10 Oct 2026 07:52:23 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-10-cve-2026-107742/</guid><description>The 10Web Booster WordPress plugin is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) via the author parameter in versions up to 2.34.8.</description><content:encoded><![CDATA[<p>The 10Web Booster - Website speed optimization, Cache &amp; Page Speed optimizer plugin for WordPress is affected by a critical Stored Cross-Site Scripting (XSS) vulnerability, tracked as CVE-2026-107742. This flaw exists in all versions up to and including 2.34.8. It stems from insufficient input sanitization and output escaping within the 'author' parameter used in comment processing. Unauthenticated attackers can inject malicious JavaScript payloads that bypass WordPress core's 'sanitize_text_field' function. The payload is successfully stored when it arrives verbatim within an 'alt' attribute, at which point the plugin's internal 'str_replace' function injects a single quote that breaks the attribute context, enabling the execution of arbitrary scripts in the browsers of users who view the affected pages. This vulnerability could lead to session hijacking, site defacement, or administrative account takeover if an administrator views the injected comment.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of an end-user's session. This poses a significant risk to site administrators, as it could facilitate the theft of session cookies, perform unauthorized actions on behalf of the administrator, or redirect users to malicious sites, potentially leading to a full site compromise.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security and IT teams to mitigate CVE-2026-107742:</p>
<ul>
<li>Update the 10Web Booster plugin to the latest available version (beyond 2.34.8) immediately.</li>
<li>Audit WordPress comment sections for anomalous entries containing suspicious attributes or event handlers (e.g., 'onmouseover', 'onerror').</li>
<li>Deploy a Web Application Firewall (WAF) rule to inspect and block incoming HTTP POST requests containing common XSS vectors (e.g., event handlers or attribute breakout attempts) directed at WordPress comment submission endpoints.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>