What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in a1post A1POST.BG Shipping for Woo a1post-bg-shipping-for-woocommerce allows Privilege Escalation.This issue affects A1POST.BG Shipping for Woo: from n/a through <= 1.5.
Explanation of Vulnerability in Simple Terms
02Summary
A1POST.BG Shipping for Woo versions 1.5 and earlier are vulnerable to cross-site request forgery (CSRF) attacks. An attacker can craft a malicious webpage that, when visited by a logged-in site administrator, performs unauthorized actions on the WooCommerce store without the admin's knowledge or consent. This could allow modification of shipping settings, order data, or other critical store configurations.
What an attacker can do
03Attacker Capabilities
Perform unauthorized actions on the WooCommerce store by tricking an admin into visiting a malicious webpage.
Potential impact on your site
04Site Impact
Attackers can modify shipping settings, orders, or other store data without your permission if an admin visits a compromised site.
Conditions required to exploit
05Prerequisites
Admin must be logged in and visit an attacker-controlled webpage or click a malicious link.
Key dates
06Disclosure timeline
February 22, 2025
CVE published
April 28, 2026
Record updated