CVE-2023-36685: WordPress CartFlows Pro Plugin <= 1.11.12 is vulnerable to Cross Site Request Forgery (CSRF)
Published Nov 30, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force US LLC CartFlows Pro allows Cross Site Request Forgery.This issue affects CartFlows Pro: from n/a through 1.11.12.
Affected Software
1 affected component
Brainstormforce Cartflows Wordpress<=1.11.12
Remediation
Information
Update to 1.11.13 or a higher version.
Event History
Nov 30, 2023
CVE Published
via MITRE·01:41 PM
Data Sourced
via MITRE·01:41 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-36685?
The severity of CVE-2023-36685 is high with a severity value of 8.8.
2
How does CVE-2023-36685 affect CartFlows Pro plugin?
CVE-2023-36685 allows for Cross-Site Request Forgery (CSRF) attacks in the CartFlows Pro plugin.
3
Which version of CartFlows Pro is affected by CVE-2023-36685?
CartFlows Pro versions up to and including 1.11.12 are affected by CVE-2023-36685.
4
What is Cross-Site Request Forgery (CSRF)?
Cross-Site Request Forgery (CSRF) is an attack that tricks the victim into submitting a malicious request, causing undesired actions to be performed on their behalf.
5
Is there a fix available for CVE-2023-36685?
Yes, a fix is available for CVE-2023-36685. Details can be found at the provided reference link.