What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Tribe Interactive Caddy – Smart Side Cart for WooCommerce.This issue affects Caddy – Smart Side Cart for WooCommerce: from n/a through 1.9.7.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in Tribe Interactive Caddy – Smart Side Cart for WooCommerce.This issue affects Caddy – Smart Side Cart for WooCommerce: from n/a through 1.9.7.
Explanation of Vulnerability in Simple Terms
Caddy – Smart Side Cart for WooCommerce versions up to 1.9.7 contain a cross-site request forgery vulnerability. An attacker can craft a malicious webpage that, when visited by a logged-in site administrator, performs unwanted actions on the store without their knowledge. The vulnerability requires the admin to visit the attacker's page while authenticated to the WordPress site.
What an attacker can do
Perform unwanted actions on the WooCommerce store by tricking an authenticated admin into visiting a malicious webpage.
Potential impact on your site
Store settings or data could be modified without the admin's consent if they visit a malicious link while logged in.
Conditions required to exploit
Admin must be logged into WordPress and visit an attacker-controlled webpage.
Key dates
External resources
Related vulnerabilities