What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Kadence WP Kadence WooCommerce Email Designer plugin <= 1.5.11 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in Kadence WP Kadence WooCommerce Email Designer plugin <= 1.5.11 versions.
Explanation of Vulnerability in Simple Terms
Kadence WooCommerce Email Designer versions up to 1.5.11 contain a cross-site request forgery vulnerability. An attacker can trick a logged-in site administrator into performing unintended actions by visiting a malicious webpage. The vulnerability requires the admin to click a link or visit a page controlled by the attacker. This can lead to unauthorized changes to email templates or plugin settings.
What an attacker can do
Trick an admin into making unintended changes to email templates or plugin settings without their knowledge.
Potential impact on your site
An attacker could modify your WooCommerce email templates or plugin configuration if an admin visits a malicious site.
Conditions required to exploit
Admin must be logged in and visit a malicious link or webpage controlled by the attacker.
Key dates
External resources
Related vulnerabilities