PT-2023-27511 · Woocommerce · Thedotstore Dynamic Pricing/Discount Rules For Woocommerce
Nguyen Thi Huyen Trang - Skalucy
+1
·
Published
2023-10-04
·
Updated
2023-10-05
·
CVE-2023-40559
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
theDotstore Dynamic Pricing and Discount Rules for WooCommerce plugin versions <= 2.4.0
Description
A Cross-Site Request Forgery (CSRF) issue affects the plugin, allowing unauthorized actions to be performed on behalf of a user without their knowledge. This can be exploited by tricking a user into performing an unintended action.
Recommendations
For versions <= 2.4.0, update to a version greater than 2.4.0 to resolve the issue.
As a temporary workaround, consider implementing additional validation and verification for requests to prevent unauthorized actions.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Thedotstore Dynamic Pricing/Discount Rules For Woocommerce