CVE-2019-15841: CSRF
Published Aug 30, 2019
·Updated
The facebook-for-woocommerce plugin before 1.9.15 for WordPress has CSRF via ajaxwooinfobannerpostclick, ajaxwooinfobannerpostxout, or ajaxfbtogglevisibility.
Affected Software
1 affected component
Facebook Facebook For Woocommerce Wordpress<1.9.15
Event History
Aug 30, 2019
CVE Published
via MITRE·04:16 PM
Data Sourced
via MITRE·04:16 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-15841?
CVE-2019-15841 is considered a medium severity vulnerability due to its potential for Cross-Site Request Forgery (CSRF).
2
How do I fix CVE-2019-15841?
To fix CVE-2019-15841, update the Facebook for WooCommerce plugin to version 1.9.15 or later.
3
What types of vulnerabilities does CVE-2019-15841 affect?
CVE-2019-15841 affects vulnerabilities related to CSRF through specific AJAX calls in the Facebook for WooCommerce plugin.
4
Which versions of Facebook for WooCommerce are vulnerable to CVE-2019-15841?
Versions of the Facebook for WooCommerce plugin prior to 1.9.15 are vulnerable to CVE-2019-15841.
5
Can CVE-2019-15841 impact my WordPress site?
Yes, CVE-2019-15841 can impact a WordPress site using the affected versions of the Facebook for WooCommerce plugin by allowing unauthorized actions.