ZeroHour

CVE-2023-5559

PoC
CVSS 3.1
9.1 critical
EPSS
3%p86
Published
()
Modified
Description

The 10Web Booster WordPress plugin before 2.24.18 does not validate the option name given to some AJAX actions, allowing unauthenticated users to delete arbitrary options from the database, leading to denial of service.

Vendors
10web
Products
10web booster
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.