First published: Thu Jun 22 2023(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce PayPal Payments plugin <= 2.0.4 versions.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
<=2.0.4 |
Update to 2.0.5 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-35917 is a Cross-Site Request Forgery (CSRF) vulnerability in the WooCommerce PayPal Payments plugin version 2.0.4 and below.
The vulnerability allows attackers to perform unauthorized actions on behalf of a logged-in user, potentially resulting in financial losses or theft of sensitive information.
CVE-2023-35917 has a severity rating of 8.8 (High).
Update the WooCommerce PayPal Payments plugin to a version higher than 2.0.4 or apply the patches provided by the plugin vendor.
Yes, you can find more information about CVE-2023-35917 at the following reference: [https://patchstack.com/database/vulnerability/woocommerce-paypal-payments/wordpress-woocommerce-paypal-payments-plugin-2-0-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve](https://patchstack.com/database/vulnerability/woocommerce-paypal-payments/wordpress-woocommerce-paypal-payments-plugin-2-0-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve)