CVE-2023-5559
10Web Booster < 2.24.18 - Unauthenticated Arbitrary Option Deletion
Record summary
CVE-2023-5559 has a selected CVSS score of 9.1 (critical); EIP currently links 1 Nuclei template.
Description
The 10Web Booster WordPress plugin before 2.24.18 does not validate the option name given to some AJAX actions, allowing unauthenticated users to delete arbitrary options from the database, leading to denial of service.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Oct 29, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
10web_boosterBrowse 10web / 10web_booster | VulnCheck | Version data not supplied | |
10Web BoosterDefault status: unaffected | CVE List | Before 2.24.18 | affected |
Nuclei templates
1ProjectDiscoveryCRITICAL10Web Booster < 2.24.18 - Unauthenticated Arbitrary Option DeletionCVSS 9.1
The 10Web Booster WordPress plugin before 2.24.18 does not validate the option name given to some AJAX actions, allowing unauthenticated users to delete arbitrary options from the database, leading to denial of service.
Impact
Unauthenticated attackers can delete arbitrary WordPress options from the database, leading to denial of service and potential site malfunction.
Remediation
Update 10Web Booster plugin to version 2.24.18 or later.
Source: ProjectDiscovery