10Web Booster < 2.24.18 - Unauthenticated Arbitrary Option Deletion
CVE-2023-5559
9.1CRITICAL
What is CVE-2023-5559?
The 10Web Booster plugin for WordPress prior to version 2.24.18 is vulnerable due to the lack of proper validation for the option names in certain AJAX actions. This flaw enables unauthenticated attackers to manipulate the plugin's functionality, which can lead to the deletion of arbitrary options from the database. Consequently, this can disrupt service availability and compromise the integrity of the website's configuration.
Affected Version(s)
10Web Booster 0 < 2.24.18