CVE-2023-3507: WooCommerce Pre-Orders < 2.0.3 - Arbitrary Pre-Order Canceling via CSRF
Published Jul 31, 2023
·Updated
The WooCommerce Pre-Orders WordPress plugin before 2.0.3 has a flawed CSRF check when canceling pre-orders, which could allow attackers to make logged in admins cancel arbitrary pre-orders via a CSRF attack
Affected Software
1 affected component
WooCommerce WooCommerce Pre-Orders WordPress<2.0.3
Event History
Jul 31, 2023
CVE Published
via MITRE·09:37 AM
Data Sourced
via MITRE·09:37 AM
DescriptionWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this flaw?
The vulnerability ID for this flaw is CVE-2023-3507.
2
What is the severity of CVE-2023-3507?
The severity of CVE-2023-3507 is medium with a CVSS score of 6.5.
3
What software is affected by CVE-2023-3507?
The WooCommerce Pre-Orders WordPress plugin versions up to 2.0.3 are affected by CVE-2023-3507.
4
How can this vulnerability be exploited?
Attackers can exploit CVE-2023-3507 by performing a CSRF attack to make logged in admins cancel arbitrary pre-orders.
5
Is there a patch available for CVE-2023-3507?
The WooCommerce Pre-Orders WordPress plugin version 2.0.3 includes a fix for CVE-2023-3507.