CVE-2023-35091: WordPress WooCommerce Stock Manager plugin <= 2.10.0 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in StoreApps Stock Manager for WooCommerce plugin <= 2.10.0 versions.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in storeapps Stock Manager for WooCommerce woocommerce-stock-manager allows Cross Site Request Forgery.This issue affects Stock Manager for WooCommerce: from n/a through <= 2.10.0.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WooCommerce Stock Manager Pluginto a version that resolves this vulnerability.Fixed in 2.11.0
Event History
Frequently Asked Questions
What is CVE-2023-35091?
CVE-2023-35091 is a Cross-Site Request Forgery (CSRF) vulnerability in the StoreApps Stock Manager for WooCommerce plugin version 2.10.0 and below.
How severe is CVE-2023-35091?
CVE-2023-35091 has a severity score of 8.8, which is considered high.
What software is affected by CVE-2023-35091?
The StoreApps Stock Manager for WooCommerce plugin versions up to and including 2.10.0 are affected by CVE-2023-35091.
What is Cross-Site Request Forgery (CSRF)?
Cross-Site Request Forgery (CSRF) is an attack that tricks the victim into submitting a malicious request.
Is there a fix available for CVE-2023-35091?
Yes, a fix is available for CVE-2023-35091. It is recommended to update to a version of the StoreApps Stock Manager for WooCommerce plugin that is higher than 2.10.0.