CVE Vulnerabilities

CVE-2023-5559

Published: Nov 27, 2023 | Modified: Nov 30, 2023
CVSS 3.x
9.1
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The 10Web Booster WordPress plugin before 2.24.18 does not validate the option name given to some AJAX actions, allowing unauthenticated users to delete arbitrary options from the database, leading to denial of service.

Affected Software

Name Vendor Start Version End Version
10web_booster 10web * 2.24.18 (excluding)

References