What the vulnerability does
01Description
Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
What the vulnerability does
Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions.
Explanation of Vulnerability in Simple Terms
A cross-site request forgery (CSRF) vulnerability in the WooCommerce shipping plugin allows an attacker to perform unauthorized actions on behalf of a logged-in site administrator. The attacker must trick an admin into visiting a malicious webpage while logged into the site. This can lead to unauthorized changes to shipping settings or other administrative functions.
What an attacker can do
Perform unauthorized administrative actions on the site by tricking a logged-in admin into visiting a malicious page.
Potential impact on your site
Attackers can modify shipping settings, rates, or other plugin configurations without your knowledge or consent.
Conditions required to exploit
Site administrator must be logged in and visit an attacker-controlled webpage; no special privileges required to craft the attack.
Key dates
External resources
Related vulnerabilities