What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce Canada Post Shipping Method.This issue affects Canada Post Shipping Method: from n/a through 2.8.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce Canada Post Shipping Method.This issue affects Canada Post Shipping Method: from n/a through 2.8.3.
Explanation of Vulnerability in Simple Terms
The Canada Post Shipping Method plugin for WooCommerce versions up to 2.8.3 is vulnerable to cross-site request forgery (CSRF). An attacker can craft a malicious link or webpage that, when visited by a logged-in site administrator, performs unwanted actions on the shipping method settings without the administrator's knowledge or consent.
What an attacker can do
Trick an admin into modifying Canada Post shipping settings via a malicious link or page.
Potential impact on your site
Shipping configuration could be altered, potentially disrupting order fulfillment or exposing sensitive carrier credentials.
Conditions required to exploit
Admin must visit attacker-controlled page while logged into WooCommerce.
Key dates
External resources
Related vulnerabilities