CVE-2023-32745: WordPress AutomateWoo plugin <= 5.7.1 - Cross Site Request Forgery (CSRF) vulnerability
Published Nov 9, 2023
·Updated
A vulnerability in Woo AutomateWoo automatewoo.This issue affects AutomateWoo: from n/a through <= 5.7.1.
Affected Software
1 affected component
WooCommerce Automatewoo Wordpress<=5.7.1
Remediation
Information
Update to 5.7.2 or a higher version.
Event History
Nov 9, 2023
CVE Published
via MITRE·08:38 PM
Data Sourced
via MITRE·08:38 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-32745?
CVE-2023-32745 is a Cross-Site Request Forgery (CSRF) vulnerability in the WooCommerce AutomateWoo plugin version 5.7.1 and below.
2
How severe is CVE-2023-32745?
CVE-2023-32745 has a severity score of 8.8 (high).
3
What is Cross-Site Request Forgery (CSRF)?
Cross-Site Request Forgery (CSRF) is a type of attack where an attacker tricks a user into performing actions on a website without their knowledge or consent.
4
Which versions of the WooCommerce AutomateWoo plugin are affected?
Versions 5.7.1 and below of the WooCommerce AutomateWoo plugin are affected by CVE-2023-32745.
5
How can I fix the CVE-2023-32745 vulnerability?
To fix the CVE-2023-32745 vulnerability, update the WooCommerce AutomateWoo plugin to a version higher than 5.7.1.