What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Octolize WooCommerce UPS Shipping – Live Rates and Access Points.This issue affects WooCommerce UPS Shipping – Live Rates and Access Points: from n/a through 2.2.4.
Explanation of Vulnerability in Simple Terms
02Summary
The WooCommerce UPS Shipping plugin through version 2.2.4 is vulnerable to cross-site request forgery (CSRF). An attacker can trick a site administrator into performing unintended actions—such as changing shipping settings or modifying UPS account credentials—by crafting a malicious link or page. The vulnerability requires the admin to visit the attacker's page while logged into WordPress.
What an attacker can do
03Attacker Capabilities
Trick an admin into changing UPS shipping settings or credentials without their knowledge.
Potential impact on your site
04Site Impact
Shipping configuration could be altered, potentially disrupting orders or exposing UPS account details.
Conditions required to exploit
05Prerequisites
Admin must be logged into WordPress and visit a page controlled by the attacker.
Key dates
06Disclosure timeline
April 10, 2024
CVE published
April 28, 2026
Record updated