What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team WooDiscuz – WooCommerce Comments.This issue affects WooDiscuz – WooCommerce Comments: from n/a through 2.3.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team WooDiscuz – WooCommerce Comments.This issue affects WooDiscuz – WooCommerce Comments: from n/a through 2.3.0.
Explanation of Vulnerability in Simple Terms
WooDiscuz allows attackers to perform unwanted actions on behalf of site visitors through cross-site request forgery (CSRF). An attacker can craft a malicious link or page that, when visited by a logged-in user, modifies comments or settings without the user's knowledge. The vulnerability affects WooDiscuz versions up to 2.3.0 and requires the victim to click a link or visit a page controlled by the attacker.
What an attacker can do
Modify or delete WooCommerce comments on behalf of a logged-in user without their consent.
Potential impact on your site
Comment spam, vandalism, or deletion of legitimate reviews without user authorization.
Conditions required to exploit
Victim must be logged in and click a malicious link or visit an attacker-controlled page.
Key dates
External resources
Related vulnerabilities