PT-2024-28595 · Woocommerce · Sender

Joshua Chan

·

Published

2024-08-26

·

Updated

2024-09-18

·

CVE-2024-39657

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce versions 2.6.18 and earlier
Description A Cross-Site Request Forgery (CSRF) issue affects the specified software, allowing for potential CSRF attacks. This issue can be exploited to perform unauthorized actions on behalf of the user.
Recommendations For versions 2.6.18 and earlier, upgrade to version 2.6.19 to remediate the issue and protect the site from potential CSRF attacks.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-39657

Affected Products

Sender