What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in WebToffee Decorator – WooCommerce Email Customizer allows Cross Site Request Forgery.This issue affects Decorator – WooCommerce Email Customizer: from n/a through 1.2.7.
Explanation of Vulnerability in Simple Terms
02Summary
Decorator – WooCommerce Email Customizer versions up to 1.2.7 contain a cross-site request forgery (CSRF) vulnerability. An attacker with low-level site access can perform unauthorized actions on behalf of logged-in users without their knowledge. The vulnerability requires the attacker to have a user account but does not require victim interaction. This can lead to unintended modifications to email customization settings.
What an attacker can do
03Attacker Capabilities
Perform unauthorized actions on behalf of logged-in users without their consent.
Potential impact on your site
04Site Impact
Logged-in users' email customization settings can be modified without their knowledge or consent.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege user account on the site; no victim interaction required.
Key dates
06Disclosure timeline
November 30, 2023
CVE published
April 28, 2026
Record updated