CVE-2023-5559: vulnerability in 10Web Booster
10Web Booster < 2.24.18 - Unauthenticated Arbitrary Option Deletion
Published · Updated
40Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 2.8%
from disclosure to weapon
Published on NVDNov 27
VulnCheckOct 29
exploitation probability
2.8%top 14% of all CVEs
observed exploitation
yesVulnCheck
The 10Web Booster WordPress plugin before 2.24.18 does not validate the option name given to some AJAX actions, allowing unauthenticated users to delete arbitrary options from the database, leading to denial of service.
Affected products
Unknown · 10Web BoosterRelated CVEs — 10Web Booster
In the same product, most dangerous first.