CVE-2021-4395: Abandoned Cart Recovery for WooCommerce <= 1.0.4 - Cross-Site Request Forgery Bypass
The Abandoned Cart Recovery for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.4. This is due to missing or incorrect nonce validation on the getitems() and extratablenav() functions. This makes it possible for unauthenticated attackers to perform read-only actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for the Abandoned Cart Recovery for WooCommerce plugin for WordPress?
The vulnerability ID for the Abandoned Cart Recovery for WooCommerce plugin for WordPress is CVE-2021-4395.
What is the severity of CVE-2021-4395?
The severity of CVE-2021-4395 is medium with a CVSS score of 6.5.
Which versions of the Abandoned Cart Recovery for WooCommerce plugin for WordPress are affected by CVE-2021-4395?
Versions up to and including 1.0.4 of the Abandoned Cart Recovery for WooCommerce plugin for WordPress are affected by CVE-2021-4395.
What is Cross-Site Request Forgery (CSRF)?
Cross-Site Request Forgery (CSRF) is a type of attack that tricks the victim into submitting a malicious request, usually through social engineering or other methods, without their knowledge or consent.
How can I fix CVE-2021-4395 in the Abandoned Cart Recovery for WooCommerce plugin for WordPress?
To fix CVE-2021-4395 in the Abandoned Cart Recovery for WooCommerce plugin for WordPress, update to a version higher than 1.0.4 that includes the necessary nonce validation fixes.