CVE-2024-11842

CVE-2024-11842: DN Shipping by Weight for WooCommerce < 1.2 - Settings Update via CSRF

Vendor Unknown
Product DN Shipping by Weight for WooCommerce
Published December 27, 2024
Last update December 27, 2024

CVSS base score

What the vulnerability does

01Description

The DN Shipping by Weight for WooCommerce WordPress plugin before 1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

Key dates

02Disclosure timeline

December 27, 2024 CVE published
December 27, 2024 Record updated