CVE-2026-65536 MEDIUM

CVE-2026-65536: WordPress افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) plugin <= 4.4.5 - Cross Site Request Forgery (CSRF) vulnerability

Vendor Mahdi Yousefi
Product افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری)
Weakness CWE-352 · CSRF
Published July 23, 2026
Last update July 23, 2026

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality None
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

What the vulnerability does

01Description

Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions.

Explanation of Vulnerability in Simple Terms

02Summary

A cross-site request forgery (CSRF) vulnerability in the WooCommerce shipping plugin allows an attacker to perform unauthorized actions on behalf of a logged-in site administrator. The attacker must trick an admin into visiting a malicious webpage while logged into the site. This can lead to unauthorized changes to shipping settings or other administrative functions.

What an attacker can do

03Attacker Capabilities

Perform unauthorized administrative actions on the site by tricking a logged-in admin into visiting a malicious page.

Potential impact on your site

04Site Impact

Attackers can modify shipping settings, rates, or other plugin configurations without your knowledge or consent.

Conditions required to exploit

05Prerequisites

Site administrator must be logged in and visit an attacker-controlled webpage; no special privileges required to craft the attack.

Key dates

06Disclosure timeline

July 23, 2026 CVE published

Related vulnerabilities

08Related CVE