CVE-2023-3508: WooCommerce Pre-Orders < 2.0.3 - Unauthorised Actions via CSRF
The WooCommerce Pre-Orders WordPress plugin before 2.0.3 has a flawed CSRF check when processing its tab actions, which could allow attackers to make logged in admins email pre-orders customer, change the released date, mark all pre-orders of a specific product as complete or cancel via CSRF attacks
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of the WooCommerce Pre-Orders WordPress plugin?
The vulnerability ID of the WooCommerce Pre-Orders WordPress plugin is CVE-2023-3508.
What is the severity level of CVE-2023-3508?
The severity level of CVE-2023-3508 is medium with a severity value of 6.5.
How does CVE-2023-3508 affect the WooCommerce Pre-Orders WordPress plugin?
CVE-2023-3508 allows attackers to make logged in admins email pre-orders customer, change the released date, mark all pre-orders of a specific product as complete, or cancel via CSRF attacks.
Which software version of the WooCommerce Pre-Orders plugin is affected by CVE-2023-3508?
The WooCommerce Pre-Orders plugin version up to and exclusive of 2.0.3 is affected by CVE-2023-3508.
How can I fix the vulnerability represented by CVE-2023-3508 in the WooCommerce Pre-Orders WordPress plugin?
Ensure you have updated the WooCommerce Pre-Orders plugin to version 2.0.3 or higher to fix the vulnerability represented by CVE-2023-3508.