Record summary

CVE-2023-5559 has a selected CVSS score of 9.1 (critical); EIP currently links 1 Nuclei template.

Description

The 10Web Booster WordPress plugin before 2.24.18 does not validate the option name given to some AJAX actions, allowing unauthenticated users to delete arbitrary options from the database, leading to denial of service.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Oct 29, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

10Web Booster

Default status: unaffected

CVE ListBefore 2.24.18affected

Nuclei templates

1
ProjectDiscoveryCRITICAL10Web Booster < 2.24.18 - Unauthenticated Arbitrary Option DeletionCVSS 9.1

The 10Web Booster WordPress plugin before 2.24.18 does not validate the option name given to some AJAX actions, allowing unauthenticated users to delete arbitrary options from the database, leading to denial of service.

Impact

Unauthenticated attackers can delete arbitrary WordPress options from the database, leading to denial of service and potential site malfunction.

Remediation

Update 10Web Booster plugin to version 2.24.18 or later.

Authorsdaffainfo
Template tagscvecve2023wordpresswp-pluginwp10webvkevintrusivevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CPE: cpe:2.3:a:10web:10web_booster:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2