๐Ÿ” CVE Alert

CVE-2026-82195

UNKNOWN 0.0

10Web Booster < 2.34.0 - Unauthenticated Connection Secret Disclosure and Deletion

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The 10Web Booster WordPress plugin before 2.34.0 does not restrict access to the routine which issues the shared secret that authenticates its cloud connection, disclosing that secret to unauthenticated visitors and letting them delete it repeatedly, preventing an administrator from completing a legitimate connection.

Vendor unknown
Product 10web booster
Published Sep 24, 2026
Stay Ahead of the Next One

Get instant alerts for unknown 10web booster

Be the first to know when new unknown vulnerabilities affecting unknown 10web booster are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / 10Web Booster
0 < 2.34.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/c6e4763e-e4db-4318-9631-06ee7426f3ae/

Credits

Shirshak Roy WPScan