PT-2026-31233 · WordPress · Dotstore Extra Fees Plugin For Woocommerce

Published

2026-04-08

·

Updated

2026-04-12

·

CVE-2026-39671

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions Dotstore Extra Fees Plugin for WooCommerce versions through 4.3.3
Description A Cross-Site Request Forgery (CSRF) vulnerability exists in the Dotstore Extra Fees Plugin for WooCommerce woo-conditional-product-fees-for-checkout. This allows attackers to perform actions on behalf of authenticated users without their knowledge.
Recommendations Update Dotstore Extra Fees Plugin for WooCommerce to a version later than 4.3.3.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2026-39671

Affected Products

Dotstore Extra Fees Plugin For Woocommerce