Access violation vulnerability in 10Web Booster – Website speed optimization, Cache & Page Speed optimizer 2.24.14

The 10Web Booster plugin for WordPress, up to and including version 2.24.14, is vulnerable to unauthorized data loss. This vulnerability makes it possible for unauthenticated attackers to delete any option values from the site. This is due to the insufficient validation of the option value being supplied to the two_init_flow_score and the two_init_flow_score functions which are hooked via nopriv AJAX.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.