WF-9c8b0de4-e3ee-4711-8f27-097dee843dd8-tenweb-speed-optimizer
10Web Booster – Website speed optimization, Cache & Page Speed optimizer <= 2.13.44 - Missing Authorization in Settings Import to Stored Cross-Site Scripting
highMissing Authorization
7.2
CVSS Score
7.2
CVSS Score
high
Severity
2.13.45
Patched in
483d
Time to patch
Description
The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check within the settings import functionality in versions up to, and including, 2.13.44. This makes it possible for unauthenticated attackers to conduct cross-site scripting attacks by injecting arbitrary web scripts in the two_delay_custom_js setting that will execute whenever a user accesses an injected page.
CVSS Vector Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:NAttack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Low
Confidentiality
Low
Integrity
None
Availability
Technical Details
Affected versions
<=2.13.44PublishedFebruary 21, 2023
Last updatedJune 17, 2024
Affected plugintenweb-speed-optimizer
Check if your site is affected.
Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.