VYPR

Boost plugin

by WordPress

CVEs (1)

  • CVE-2026-9010HigMay 20, 2026
    risk 0.49cvss 7.5epss 0.00

    The Boost plugin for WordPress is vulnerable to time-based SQL Injection via the 'current_url' and 'user_name' parameters in versions up to, and including, 2.0.3 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL…