← back
CVE-2023-5559observed exploitation

10Web Booster < 2.24.18 - Unauthenticated Arbitrary Option Deletion

40Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 2.8%
from disclosure to weapon
Published on NVDNov 27
VulnCheckOct 29
exploitation probability
2.8%top 15% of all CVEs
observed exploitation
yesVulnCheck
The 10Web Booster WordPress plugin before 2.24.18 does not validate the option name given to some AJAX actions, allowing unauthenticated users to delete arbitrary options from the database, leading to denial of service.
Affected products
Unknown · 10Web Booster