Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-86449
HistoryNov 23, 2022 - 12:00 a.m.

WordPress Booster for WooCommerce plugin cross-site request forgery vulnerability

2022-11-2300:00:00
China National Vulnerability Database
www.cnvd.org.cn
5
wordpress
woocommerce
csrf
vulnerability
cross-site request forgery
php
deletion
attack
plugin

EPSS

0.001

Percentile

37.9%

WordPress and WordPress plugin are both products of the WordPress Foundation. WordPress is a set of blogging platforms developed using the PHP language. WordPress plugin is an application plugin. WordPress Booster for WooCommerce plugin has a cross-site request forgery vulnerability that stems from the fact that the plugin does not perform CSRF checks when deleting files uploaded by Deletion, and an attacker uses the vulnerability to launch a cross-site request forgery attack.

EPSS

0.001

Percentile

37.9%