Overview
The 10Web Booster plugin for WordPress, a tool designed to speed up websites, has a serious security flaw. This flaw allows attackers to delete any folder on your server, even critical system folders. If exploited, this could lead to significant data loss or completely shut down your website. The problem lies in how the plugin handles file paths when clearing its cache.
CVE Details
- Product: 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress
- CVE ID: CVE-2025-13377
- Published: December 6, 2025
- Severity: CRITICAL
- Status: Analyzed
Affected Products
All versions of the 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress up to, and including, version 2.32.7 are affected by this vulnerability.
Current Status
This vulnerability has been analyzed. A fix is available in a newer version of the plugin.
Severity Level
Rated as CRITICAL, this vulnerability poses a very high risk. An attacker only needs a low-level account (like a Subscriber) on your WordPress site to exploit it. Because they can delete arbitrary folders, they could wipe out website data, crucial operating system files, or cause a denial of service, making your website unavailable to visitors.
Possible Solutions
The developers of the 10Web Booster plugin have released an update that addresses this vulnerability. To protect your WordPress site, you must update the plugin to version 2.32.11 or higher immediately. This update includes improved security during cache clearing, specifically by adding robust file path validation to prevent unauthorized directory deletion.
References
https://plugins.trac.wordpress.org/changeset/3402434/tenweb-speed-optimizer
https://www.wordfence.com/threat-intel/vulnerabilities/id/f8bcf51a-36ee-4d4d-b9d6-d9db0dafd791?source=cve


