PT-2024-22430 · WordPress · Woocommerce Customers Manager

Bob Matyas

·

Published

2024-08-01

·

Updated

2025-05-29

·

CVE-2024-2843

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions WooCommerce Customers Manager WordPress plugin versions prior to 30.1
Description The issue concerns a lack of CSRF checks in certain areas of the plugin, which could allow attackers to make logged-in admin users delete users via CSRF attacks. This could enable attackers to forge malicious requests.
Recommendations For versions prior to 30.1, upgrade the affected plugin immediately to mitigate risks. As a temporary workaround, consider restricting access to user management functions to minimize the risk of exploitation.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-2843

Affected Products

Woocommerce Customers Manager