CVE-2023-0503

CVE-2023-0503: Free WooCommerce Theme 99fy Extension < 1.2.8 - Arbitrary Plugin Activation via CSRF

Vendor Unknown
Product Free WooCommerce Theme 99fy Extension
Published March 27, 2023
Last update February 19, 2025

CVSS base score

What the vulnerability does

01Description

The Free WooCommerce Theme 99fy Extension WordPress plugin before 1.2.8 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

Key dates

02Disclosure timeline

March 27, 2023 CVE published
February 19, 2025 Record updated