CVE-2026-82195
10Web Booster < 2.34.0 - Unauthenticated Connection Secret Disclosure and Deletion
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The 10Web Booster WordPress plugin before 2.34.0 does not restrict access to the routine which issues the shared secret that authenticates its cloud connection, disclosing that secret to unauthenticated visitors and letting them delete it repeatedly, preventing an administrator from completing a legitimate connection.
| Vendor | unknown |
| Product | 10web booster |
| Published | Sep 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown 10web booster
Be the first to know when new unknown vulnerabilities affecting unknown 10web booster are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / 10Web Booster
0 < 2.34.0
References
Credits
Shirshak Roy WPScan