First published: Mon Jul 17 2023(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Brands plugin <= 1.6.49 versions.
Credit: audit@patchstack.com audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Woocommerce Brands | <1.6.50 |
Update to 1.6.50 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-35880 is high.
The affected software of CVE-2023-35880 is WooCommerce Brands plugin version 1.6.49 and below.
The Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Brands plugin allows an attacker to perform actions on behalf of an authenticated user without their knowledge or consent.
Yes, a fix is available for CVE-2023-35880. It is recommended to update to WooCommerce Brands plugin version 1.6.50 or higher.
You can find more information about CVE-2023-35880 at the following link: [https://patchstack.com/database/vulnerability/woocommerce-brands/wordpress-woocommerce-brands-plugin-1-6-49-cross-site-request-forgery-csrf-vulnerability](https://patchstack.com/database/vulnerability/woocommerce-brands/wordpress-woocommerce-brands-plugin-1-6-49-cross-site-request-forgery-csrf-vulnerability?_s_id=cve)