cleantalk
Vulnerabilities and Security Researches

10Web Booster – Website speed optimization, Cache & Page Speed optimizer, CVE-2023-5559

CVE, Research URL

CVE-2023-5559

Published on
Nov 27, 2023
Research Description
The 10Web Booster WordPress plugin before 2.24.18 does not validate the option name given to some AJAX actions, allowing unauthenticated users to delete arbitrary options from the database, leading to denial of service.
Affected versions
max 2.24.18.
Status
vulnerable