Vulnerability Description
The 10Web Booster WordPress plugin before 2.24.18 does not validate the option name given to some AJAX actions, allowing unauthenticated users to delete arbitrary options from the database, leading to denial of service.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| 10Web | 10Web Booster | < 2.24.18 |
References
- https://wpscan.com/vulnerability/eba46f7d-e4db-400c-8032-015f21087bbfExploitThird Party Advisory
- https://wpscan.com/vulnerability/eba46f7d-e4db-400c-8032-015f21087bbfExploitThird Party Advisory
FAQ
What is CVE-2023-5559?
CVE-2023-5559 is a vulnerability with a CVSS score of 9.1 (CRITICAL). The 10Web Booster WordPress plugin before 2.24.18 does not validate the option name given to some AJAX actions, allowing unauthenticated users to delete arbitrary options from the database, leading to...
How severe is CVE-2023-5559?
CVE-2023-5559 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-5559?
Check the references section above for vendor advisories and patch information. Affected products include: 10Web 10Web Booster.