CVE-2026-94121: WordPress 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin <= 2.33.6 - PHP Object Injection vulnerability
Published Sep 30, 2026
·Updated
Contributor PHP Object Injection in 10Web Booster – Website speed optimization, Cache & Page Speed optimizer <= 2.33.6 versions.
Affected Software
1 affected component
10web 10Web Booster<=2.33.6
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
10Web Booster – Website speed optimization, Cache & Page Speed optimizerto a version that resolves this vulnerability.Fixed in 2.34.0
Event History
Sep 30, 2026
CVE Published
via MITRE·12:27 PM
Data Sourced
via MITRE·12:27 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this vulnerability?
An attacker needs Contributor-level privileges on a WordPress site using the affected 10Web Booster plugin. The CVSS vector indicates exploitation can be performed remotely without user interaction.
2
What is the impact if exploitation succeeds?
The reported impact includes high confidentiality, integrity, and availability effects. The vulnerability is classified as PHP object injection.
3
Which plugin versions are affected?
10Web Booster versions 2.33.6 and earlier are identified as affected.