First published: Thu Nov 09 2023(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce AutomateWoo plugin <= 5.7.1 versions.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Woocommerce Automatewoo | <=5.7.1 |
Update to 5.7.2 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-32745 is a Cross-Site Request Forgery (CSRF) vulnerability in the WooCommerce AutomateWoo plugin version 5.7.1 and below.
CVE-2023-32745 has a severity score of 8.8 (high).
Cross-Site Request Forgery (CSRF) is a type of attack where an attacker tricks a user into performing actions on a website without their knowledge or consent.
Versions 5.7.1 and below of the WooCommerce AutomateWoo plugin are affected by CVE-2023-32745.
To fix the CVE-2023-32745 vulnerability, update the WooCommerce AutomateWoo plugin to a version higher than 5.7.1.