What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in weightbasedshipping.Com WooCommerce Weight Based Shipping plugin <= 5.4.1 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in weightbasedshipping.Com WooCommerce Weight Based Shipping plugin <= 5.4.1 versions.
Explanation of Vulnerability in Simple Terms
WooCommerce Weight Based Shipping versions up to 5.4.1 are vulnerable to cross-site request forgery (CSRF). An attacker can craft a malicious link or page that, when visited by a logged-in site administrator, performs unauthorized actions on the plugin's settings. The vulnerability requires the admin to click the link but does not require the attacker to have site access.
What an attacker can do
Perform unauthorized actions on the plugin's settings by tricking a logged-in admin into clicking a malicious link.
Potential impact on your site
An attacker could modify shipping settings or other plugin configuration without your knowledge if you click a malicious link while logged in.
Conditions required to exploit
Target must be a logged-in WooCommerce admin with low or higher privileges; attacker needs to trick them into visiting a malicious page.
Key dates
External resources
Related vulnerabilities