CVE-2023-5559
10Web Booster < 2.24.18 - Unauthenticated Arbitrary Option Deletion
Vexday Risk Score
18Low
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS —EPSS 2.8%KEV nãoPoC —Nuclei simMetasploit —Patch —
Lifecycle
27 Nov 2023Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
The 10Web Booster WordPress plugin before 2.24.18 does not validate the option name given to some AJAX actions, allowing unauthenticated users to delete arbitrary options from the database, leading to denial of service.
Affected products
Unknown · 10Web BoosterWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →