Show plain JSON{"dataType": "CVE_RECORD", "dataVersion": "5.1", "cveMetadata": {"cveId": "CVE-2023-5559", "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81", "state": "PUBLISHED", "assignerShortName": "WPScan", "dateReserved": "2023-10-12T14:55:58.100Z", "datePublished": "2023-11-27T16:22:06.218Z", "dateUpdated": "2024-08-02T07:59:44.808Z"}, "containers": {"cna": {"providerMetadata": {"orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81", "shortName": "WPScan", "dateUpdated": "2023-11-27T16:22:06.218Z"}, "title": "10Web Booster < 2.24.18 - Unauthenticated Arbitrary Option Deletion", "problemTypes": [{"descriptions": [{"description": "CWE-862 Missing Authorization", "lang": "en", "type": "CWE"}]}], "affected": [{"vendor": "Unknown", "product": "10Web Booster", "versions": [{"status": "affected", "versionType": "semver", "version": "0", "lessThan": "2.24.18"}], "defaultStatus": "unaffected", "collectionURL": "https://wordpress.org/plugins"}], "descriptions": [{"lang": "en", "value": "The 10Web Booster WordPress plugin before 2.24.18 does not validate the option name given to some AJAX actions, allowing unauthenticated users to delete arbitrary options from the database, leading to denial of service."}], "references": [{"url": "https://wpscan.com/vulnerability/eba46f7d-e4db-400c-8032-015f21087bbf", "tags": ["exploit", "vdb-entry", "technical-description"]}], "credits": [{"lang": "en", "value": "Krzysztof Zaj\u0105c", "type": "finder"}, {"lang": "en", "value": "WPScan", "type": "coordinator"}], "source": {"discovery": "EXTERNAL"}, "x_generator": {"engine": "WPScan CVE Generator"}}, "adp": [{"providerMetadata": {"orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-02T07:59:44.808Z"}, "title": "CVE Program Container", "references": [{"url": "https://wpscan.com/vulnerability/eba46f7d-e4db-400c-8032-015f21087bbf", "tags": ["exploit", "vdb-entry", "technical-description", "x_transferred"]}]}]}}