---
id: CVE-2026-82195
title: >-
  The 10Web Booster  WordPress plugin before 2.34.0 does not restrict access to
  the routine which issues the shared secret that authenticates its cloud
  connection, disclosing that secret to unauthenticated visitors and letting
  them delete …
summary: >-
  The 10Web Booster  WordPress plugin before 2.34.0 does not restrict access to
  the routine which issues the shared secret that authenticates its cloud
  connection, disclosing that secret to unauthenticated visitors and letting
  them delete …
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L'
cwe:
  - CWE-862
product: 10Web Booster
affected:
  - 10web_booster < 2.34.0
published: '2026-09-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T14:42:02.707'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82195'
references:
  - url: 'https://wpscan.com/vulnerability/c6e4763e-e4db-4318-9631-06ee7426f3ae/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-24T10:36:40.745716Z'
ingestedAt: '2026-09-24T06:39:26.612Z'
epss: 0.00227
epssPercentile: 0.12014
---

## Overview

The 10Web Booster  WordPress plugin before 2.34.0 does not restrict access to the routine which issues the shared secret that authenticates its cloud connection, disclosing that secret to unauthenticated visitors and letting them delete it repeatedly, preventing an administrator from completing a legitimate connection.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
