What is CVE-2026-14287?
The CVE-2026-14287 vulnerability in the 10Web Booster WordPress plugin before version 2.33.5 involves improper access token validation on an unauthenticated request handler and failure to escape attacker-supplied stylesheet content before rendering it into the page head. This allows an unauthenticated attacker to store markup that executes as JavaScript in the page. Immediate update to version 2.33.5 or later is recommended.
Azərbaycanca: CVE-2026-14287 boşluğu 10Web Booster WordPress plugin-in 2.33.5 öncəsi versiyalarında autentifikasiya olunmamış tələb idarəçisində access token yoxlanışını düzgün aparmaması və istifadəçi tərəfindən təqdim edilən stil cədvəli məzmununu səhifəyə yerləşdirməzdən əvvəl escapə etməməsi ilə bağlıdır. Bu, autentifikasiya olunmamış hücumçunun səhifəyə JavaScript kimi icra olunan markup yerləşdirməsinə şərait yaradır. Plugin-i dərhal 2.33.5 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which WordPress plugin is affected by CVE-2026-14287 and what is the safe version?
The CVE-2026-14287 vulnerability affects the 10Web Booster plugin before version 2.33.5. An immediate update to version 2.33.5 or later is recommended for secure usage.
What does the CVE-2026-14287 vulnerability allow an unauthenticated attacker to do?
The CVE-2026-14287 vulnerability allows an unauthenticated attacker to store markup that executes as JavaScript in the page. This happens due to improper access token validation and failure to escape attacker-supplied stylesheet content before rendering it.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.