CVE-2026-32556: WordPress Boost plugin <= 2.0.4 - Cross Site Scripting (XSS) vulnerability
Published Aug 24, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.
Affected Software
1 affected component
WordPress Boost plugin<=2.0.4
Event History
Aug 24, 2026
CVE Published
via MITRE·09:31 PM
Data Sourced
via MITRE·09:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is described as unauthenticated, so an attacker does not need a WordPress account or prior privileges. Exploitation still requires user interaction, as indicated by the UI:R vector.
2
What security impact can successful exploitation have?
The supplied CVSS vector indicates low confidentiality, integrity, and availability impact, with scope changed. This is an XSS vulnerability, meaning attacker-supplied script could execute in a victim's browser in the affected application context.
3
Which plugin versions are affected?
Boost plugin versions 2.0.4 and earlier are identified as affected. No fixed version is provided in the available data.