CVE-2023-48284 MEDIUM

CVE-2023-48284: WordPress Decorator – WooCommerce Email Customizer Plugin <= 1.2.7 is vulnerable to Cross Site Request Forgery (CSRF)

Vendor Webtoffee
Product Decorator – WooCommerce Email Customizer
Weakness CWE-352 · CSRF
Published November 30, 2023
Last update April 28, 2026

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

What the vulnerability does

01Description

Cross-Site Request Forgery (CSRF) vulnerability in WebToffee Decorator – WooCommerce Email Customizer allows Cross Site Request Forgery.This issue affects Decorator – WooCommerce Email Customizer: from n/a through 1.2.7.

Explanation of Vulnerability in Simple Terms

02Summary

Decorator – WooCommerce Email Customizer versions up to 1.2.7 contain a cross-site request forgery (CSRF) vulnerability. An attacker with low-level site access can perform unauthorized actions on behalf of logged-in users without their knowledge. The vulnerability requires the attacker to have a user account but does not require victim interaction. This can lead to unintended modifications to email customization settings.

What an attacker can do

03Attacker Capabilities

Perform unauthorized actions on behalf of logged-in users without their consent.

Potential impact on your site

04Site Impact

Logged-in users' email customization settings can be modified without their knowledge or consent.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege user account on the site; no victim interaction required.

Key dates

06Disclosure timeline

November 30, 2023 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE