Lucene search

K
wpvulndbWpvulndbWPVDB-ID:9AB2147B-585D-4667-A26B-868AE96924E4
HistoryOct 30, 2022 - 12:00 a.m.

Advanced Dynamic Pricing for WooCommerce < 4.1.6 - Settings Import via CSRF

2022-10-3000:00:00
wpscan.com
11
woocommerce
dynamic pricing
csrf
security vulnerability
admin
attack

EPSS

0.001

Percentile

20.9%

The plugin does not have CSRF check in place when importing its settings, which could allow attackers to make a logged in admin import them via a CSRF attack

EPSS

0.001

Percentile

20.9%

Related for WPVDB-ID:9AB2147B-585D-4667-A26B-868AE96924E4