Description
The 10Web Booster WordPress plugin before 2.24.18 does not validate the option name given to some AJAX actions, allowing unauthenticated users to delete arbitrary options from the database, leading to denial of service.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-57859 | The 10Web Booster WordPress plugin before 2.24.18 does not validate the option name given to some AJAX actions, allowing unauthenticated users to delete arbitrary options from the database, leading to denial of service. |
References
History
No history.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-02T07:59:44.808Z
Reserved: 2023-10-12T14:55:58.100Z
Link: CVE-2023-5559
No data.
Status : Modified
Published: 2023-11-27T17:15:08.927
Modified: 2024-11-21T08:42:00.973
Link: CVE-2023-5559
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD