CVE-2023-34386: WordPress WPC Smart Wishlist for WooCommerce plugin <= 4.7.1 - Cross Site Request Forgery (CSRF) vulnerability
Published Nov 9, 2023
·Updated
A vulnerability in WPClever WPC Smart Wishlist for WooCommerce woo-smart-wishlist.This issue affects WPC Smart Wishlist for WooCommerce: from n/a through <= 4.7.1.
Affected Software
1 affected component
WPClever Wpc Smart Wishlist For Woocommerce Wordpress<4.7.2
Remediation
Information
Update to 4.7.2 or a higher version.
Event History
Nov 9, 2023
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-34386?
The severity of CVE-2023-34386 is high with a severity value of 8.8.
2
What is the vulnerability description of CVE-2023-34386?
CVE-2023-34386 is a Cross-Site Request Forgery (CSRF) vulnerability in the WPClever WPC Smart Wishlist for WooCommerce plugin <= 4.7.1 versions.
3
What software versions are affected by CVE-2023-34386?
The WPClever WPC Smart Wishlist for WooCommerce plugin versions up to and excluding 4.7.2 are affected by CVE-2023-34386.
4
How can I fix CVE-2023-34386?
To fix CVE-2023-34386, update the WPClever WPC Smart Wishlist for WooCommerce plugin to version 4.7.2 or later.
5
What does CWE-352 refer to in relation to CVE-2023-34386?
CWE-352 refers to Cross-Site Request Forgery (CSRF) in CVE-2023-34386.