CVE-2023-36513: WordPress AutomateWoo Plugin <= 5.7.5 is vulnerable to Cross Site Request Forgery (CSRF)
Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce AutomateWoo plugin <= 5.7.5 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
woocommerce/automatewooto a version that resolves this vulnerability.Fixed in 5.7.6
Event History
Frequently Asked Questions
What is the severity of CVE-2023-36513?
The severity of CVE-2023-36513 is high with a severity value of 8.8.
What is the vulnerability in WooCommerce AutomateWoo plugin?
The vulnerability in WooCommerce AutomateWoo plugin is a Cross-Site Request Forgery (CSRF) vulnerability.
Which versions of WooCommerce AutomateWoo plugin are affected by CVE-2023-36513?
WooCommerce AutomateWoo plugin versions up to and including 5.7.5 are affected by CVE-2023-36513.
How can I fix CVE-2023-36513?
To fix CVE-2023-36513, update WooCommerce AutomateWoo plugin to a version higher than 5.7.5.
Where can I find more information about CVE-2023-36513?
You can find more information about CVE-2023-36513 at the following link: [CVE-2023-36513](https://patchstack.com/database/vulnerability/automatewoo/wordpress-automatewoo-plugin-5-7-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve)