10Web Booster Arbitrary Folder Deletion Vulnerability (CVE-2025-13377) — Critical Severity

Overview

The 10Web Booster plugin for WordPress, a tool designed to speed up websites, has a serious security flaw. This flaw allows attackers to delete any folder on your server, even critical system folders. If exploited, this could lead to significant data loss or completely shut down your website. The problem lies in how the plugin handles file paths when clearing its cache.

CVE Details

  • Product: 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress
  • CVE ID: CVE-2025-13377
  • Published: December 6, 2025
  • Severity: CRITICAL
  • Status: Analyzed

Affected Products

All versions of the 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress up to, and including, version 2.32.7 are affected by this vulnerability.

Current Status

This vulnerability has been analyzed. A fix is available in a newer version of the plugin.

Severity Level

Rated as CRITICAL, this vulnerability poses a very high risk. An attacker only needs a low-level account (like a Subscriber) on your WordPress site to exploit it. Because they can delete arbitrary folders, they could wipe out website data, crucial operating system files, or cause a denial of service, making your website unavailable to visitors.

Possible Solutions

The developers of the 10Web Booster plugin have released an update that addresses this vulnerability. To protect your WordPress site, you must update the plugin to version 2.32.11 or higher immediately. This update includes improved security during cache clearing, specifically by adding robust file path validation to prevent unauthorized directory deletion.

References

https://plugins.trac.wordpress.org/changeset/3402434/tenweb-speed-optimizer
https://www.wordfence.com/threat-intel/vulnerabilities/id/f8bcf51a-36ee-4d4d-b9d6-d9db0dafd791?source=cve

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.