CVE-2026-32555: WordPress Boost plugin <= 2.0.4 - SQL Injection vulnerability
Published Aug 24, 2026
·Updated
Unauthenticated SQL Injection in Boost <= 2.0.4 versions.
Affected Software
1 affected component
WordPress Boost plugin<=2.0.4
Event History
Aug 24, 2026
CVE Published
via MITRE·09:31 PM
Data Sourced
via MITRE·09:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or other prior privileges to attempt exploitation.
2
Which plugin versions are affected?
Boost versions 2.0.4 and earlier are identified as affected.
3
What is the potential impact?
The supplied severity vector indicates network-reachable exploitation with low attack complexity, no privileges or user interaction required, and high confidentiality impact. It also indicates a low availability impact and no integrity impact.