OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-94121

HIGH · CVSS 8.8 EPSS 0.38%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The vulnerability affects versions 2.33.6 and earlier of the 10Web Booster plugin, which is used for website speed optimization and caching. It allows for PHP Object Injection, potentially enabling attackers to execute arbitrary code, leading to severe security breaches. Website administrators using this plugin should prioritize patching or upgrading to mitigate the risk.

CVE
CVE-2026-94121
Severity
HIGH
CVSS
8.8
EPSS
0.38%

Original NVD Description

Contributor PHP Object Injection in 10Web Booster – Website speed optimization, Cache & Page Speed optimizer <= 2.33.6 versions.