PT-2024-12953 · Woocommerce · Abandoned Cart Lite For Woocommerce
Mika
·
Published
2024-12-13
·
Updated
2024-12-17
·
CVE-2023-41671
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Abandoned Cart Lite for WooCommerce versions n/a through 5.16.1
Description
The issue affects Abandoned Cart Lite for WooCommerce due to a Missing Authorization vulnerability, allowing exploitation of incorrectly configured access control security levels. This vulnerability can be exploited through Cross-Site Request Forgery (CSRF).
Recommendations
Update to the latest version to secure your site.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Abandoned Cart Lite For Woocommerce