First published: Fri Aug 30 2019(Updated: )
The facebook-for-woocommerce plugin before 1.9.15 for WordPress has CSRF via ajax_woo_infobanner_post_click, ajax_woo_infobanner_post_xout, or ajax_fb_toggle_visibility.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Facebook for WooCommerce | <1.9.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-15841 is considered a medium severity vulnerability due to its potential for Cross-Site Request Forgery (CSRF).
To fix CVE-2019-15841, update the Facebook for WooCommerce plugin to version 1.9.15 or later.
CVE-2019-15841 affects vulnerabilities related to CSRF through specific AJAX calls in the Facebook for WooCommerce plugin.
Versions of the Facebook for WooCommerce plugin prior to 1.9.15 are vulnerable to CVE-2019-15841.
Yes, CVE-2019-15841 can impact a WordPress site using the affected versions of the Facebook for WooCommerce plugin by allowing unauthorized actions.