CVE-2026-14287
Last modified
CVE-2026-14287 is a medium-severity vulnerability rated 4.7/10 on the CVSS scale. The 10Web Booster WordPress plugin before 2.33.5 does not correctly validate an access token on an unauthenticated request handler and does not escape attacker-supplied stylesheet content before rendering it into the page head, allowing an unauthenticated attacker to store markup that executes as JavaScript in the browser of anonymous visitors to an affected page.. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
The 10Web Booster WordPress plugin before 2.33.5 does not correctly validate an access token on an unauthenticated request handler and does not escape attacker-supplied stylesheet content before rendering it into the page head, allowing an unauthenticated attacker to store markup that executes as JavaScript in the browser of anonymous visitors to an affected page.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Unknown | 10Web Booster | < 2.33.5 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-14287?
How severe is CVE-2026-14287?
How do I fix CVE-2026-14287?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-14278Rejected reason: After further coordination, CVE was determi…
- CVE-2026-14279The Wholesale Market plugin for WordPress is vulnerable to p…8.8
- CVE-2026-1428Single Sign-On Portal System developed by WellChoose has a O…8.8
- CVE-2026-14280The Events Manager – Calendar, Bookings, Tickets, and more! …6.6
- CVE-2026-14282The GoDAM – Organize WordPress Media Library & File Manager …9.8
- CVE-2026-14286Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-14289The FacturaONE para WooCommerce con VeriFactu WordPress plug…9
- CVE-2026-1429Single Sign-On Portal System developed by WellChoose has a R…5.4
- CVE-2026-14290The Embed Google Photos album WordPress plugin through 2.2.1…6.8
- CVE-2026-14291The security-ninja-premium WordPress plugin before 5.290 doe…7.5
- CVE-2026-14292The Download Manager WordPress plugin before 3.3.66 does not…5.4
- CVE-2026-14293The Autopay WordPress plugin before 5.0.1 does not perform a…8.8
Are you affected by CVE-2026-14287?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
