CVE-2025-13377: 10Web Booster <= 2.32.7 - Authenticated (Subscriber+) Arbitrary Folder Deletion via two_clear_page_cache
The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is vulnerable to arbitrary folder deletion due to insufficient file path validation in the getcachedirforpagefromurl() function in all versions up to, and including, 2.32.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary folders on the server, which can easily lead to a loss of data or a denial of service condition.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13377?
CVE-2025-13377 is considered a critical vulnerability due to the potential for arbitrary folder deletion.
How do I fix CVE-2025-13377?
To fix CVE-2025-13377, update the 10Web Booster plugin to version 2.32.8 or later.
What versions are affected by CVE-2025-13377?
CVE-2025-13377 affects all versions of the 10Web Booster plugin up to and including version 2.32.7.
What impact does CVE-2025-13377 have on WordPress sites?
CVE-2025-13377 allows attackers to delete arbitrary folders on a WordPress site, leading to potential data loss and site down-time.
Is CVE-2025-13377 an issue for all WordPress sites using the plugin?
Yes, any WordPress site using the affected versions of the 10Web Booster plugin is vulnerable to CVE-2025-13377.