What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in RedNao Extra Product Options Builder for WooCommerce.This issue affects Extra Product Options Builder for WooCommerce: from n/a through 1.2.104.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in RedNao Extra Product Options Builder for WooCommerce.This issue affects Extra Product Options Builder for WooCommerce: from n/a through 1.2.104.
Explanation of Vulnerability in Simple Terms
The Extra Product Options Builder for WooCommerce plugin through version 1.2.104 is vulnerable to cross-site request forgery (CSRF). An attacker can trick a site administrator into performing unintended actions, such as modifying product options or settings, by crafting a malicious link or page. The vulnerability requires the admin to visit the attacker's page while logged in.
What an attacker can do
Trick a logged-in admin into modifying product options or plugin settings without their knowledge.
Potential impact on your site
Product configurations or plugin settings could be altered by an attacker without your consent or awareness.
Conditions required to exploit
Admin must be logged in and visit a page controlled by the attacker (e.g., click a malicious link).
Key dates
External resources
Related vulnerabilities