PT-2024-17290 · WordPress · Dn Shipping By Weight

Bob Matyas

·

Published

2024-12-27

·

Updated

2025-05-17

·

CVE-2024-11842

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions DN Shipping by Weight for WooCommerce WordPress plugin version 1.2 and earlier
Description The issue concerns the lack of CSRF verification when updating the plugin's settings. This could allow attackers to make a logged-in administrator change the settings via a CSRF attack. There is no information provided about the estimated number of potentially affected devices or real-world incidents where this issue was exploited.
Recommendations For versions prior to 1.2, update to version 1.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the settings update functionality until a patch is available. Avoid using the plugin's settings update feature until the issue is resolved.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-11842

Affected Products

Dn Shipping By Weight