CVE-2026-82195: 10Web Booster < 2.34.0 - Unauthenticated Connection Secret Disclosure and Deletion
The 10Web Booster WordPress plugin before 2.34.0 does not restrict access to the routine which issues the shared secret that authenticates its cloud connection, disclosing that secret to unauthenticated visitors and letting them delete it repeatedly, preventing an administrator from completing a legitimate connection.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
10Web Boosterto a version that resolves this vulnerability.Fixed in 2.34.0
Event History
Frequently Asked Questions
Who is exposed to this issue?
WordPress sites running 10Web Booster versions before 2.34.0 are exposed. Because the affected routine lacks access restrictions, unauthenticated visitors can reach it.
What does an attacker need to exploit it?
An attacker does not need to authenticate. They need only be able to access the affected WordPress site and invoke the routine that issues the cloud-connection shared secret.
What can an attacker do with the exposed functionality?
They can obtain the shared secret used to authenticate the plugin's cloud connection. They can also repeatedly delete the secret, which can stop an administrator from completing a legitimate connection.
Is a default configuration affected?
The available information identifies affected plugin versions before 2.34.0 but does not describe any configuration prerequisite. Sites using those versions should treat the issue as applicable unless they can confirm the affected cloud-connection functionality is unavailable.