First published: Thu Nov 09 2023(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in WPClever WPC Smart Wishlist for WooCommerce plugin <= 4.7.1 versions.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wpclever WPC Smart Wishlist for WooCommerce | <4.7.2 |
Update to 4.7.2 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-34386 is high with a severity value of 8.8.
CVE-2023-34386 is a Cross-Site Request Forgery (CSRF) vulnerability in the WPClever WPC Smart Wishlist for WooCommerce plugin <= 4.7.1 versions.
The WPClever WPC Smart Wishlist for WooCommerce plugin versions up to and excluding 4.7.2 are affected by CVE-2023-34386.
To fix CVE-2023-34386, update the WPClever WPC Smart Wishlist for WooCommerce plugin to version 4.7.2 or later.
CWE-352 refers to Cross-Site Request Forgery (CSRF) in CVE-2023-34386.