Input validation vulnerability in 10Web Booster – Website speed optimization, Cache & Page Speed optimizer 2.12.22

The 10Web Booster Website speed optimization, Cache & Page Speed optimizer plugin for WordPress, up to and including version 2.12.23, is vulnerable to a type of cyber attack called SQL Injection. This attack can be used by unauthenticated attackers to access sensitive information stored in the plugin’s database. The vulnerability is caused by the plugin not properly escaping user supplied parameters, and not properly preparing existing SQL queries.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.