CVE-2018-11633: CSRF
An issue was discovered in the MULTIDOTS Woo Checkout for Digital Goods plugin 2.1 for WordPress. If an admin user can be tricked into visiting a crafted URL created by an attacker (via spear phishing/social engineering), the attacker can change the plugin settings. The function woocheckoutsettingspage in the file class-woo-checkout-for-digital-goods-admin.php doesn't do any check against wp-admin/admin-post.php Cross-site request forgery (CSRF) and user capabilities.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue in the MULTIDOTS Woo Checkout for Digital Goods plugin?
The vulnerability ID for this issue in the MULTIDOTS Woo Checkout for Digital Goods plugin is CVE-2018-11633.
What is the severity level of CVE-2018-11633?
The severity level of CVE-2018-11633 is medium with a severity value of 6.5.
How can an attacker exploit CVE-2018-11633?
An attacker can exploit CVE-2018-11633 by tricking an admin user into visiting a crafted URL created by the attacker, typically through spear phishing or social engineering.
What can an attacker do if they exploit CVE-2018-11633?
If an attacker successfully exploits CVE-2018-11633, they can change the plugin settings in the MULTIDOTS Woo Checkout for Digital Goods plugin.
Is there a fix or patch available for CVE-2018-11633?
Yes, you can find the fix or patch for CVE-2018-11633 on the official WordPress plugin page for MULTIDOTS Woo Checkout for Digital Goods.