← back
CVE-2023-5559

10Web Booster < 2.24.18 - Unauthenticated Arbitrary Option Deletion

EPSS 2.8%
Vexday Risk Score
18Low
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS EPSS 2.8%KEV nãoPoC Nuclei simMetasploit Patch
Lifecycle
27 Nov 2023Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
The 10Web Booster WordPress plugin before 2.24.18 does not validate the option name given to some AJAX actions, allowing unauthenticated users to delete arbitrary options from the database, leading to denial of service.
Affected products
Unknown · 10Web Booster

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →