← voltar
CVE-2023-5979

eCommerce Product Catalog Plugin for WordPress < 3.3.26 - Products Deletion via CSRF

EPSS 0.3%
Vexday Risk Score
3Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
04 dez 2023Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
The eCommerce Product Catalog Plugin for WordPress plugin before 3.3.26 does not have CSRF checks in some of its admin pages, which could allow attackers to make logged-in users perform unwanted actions via CSRF attacks, such as delete all products