
CVE-2026-9010 The Boost plugin for WordPress is vulnerable to time-based SQL Injection via the 'current_url' and 'user_name' parameters in versions up to, and including, 2.0.3 due to… https://www.cve.org/CVERecord?id=CVE-2026-9010
Post summary
The post announces that the Boost WordPress plugin up to version 2.0.3 has a time‑based SQL Injection vulnerability via specific parameters, providing technical details but no exploit or patch information.
