CVE-2023-40212: WordPress WooCommerce Product Attachment Plugin <= 2.1.8 is vulnerable to Cross Site Request Forgery (CSRF)
Published Oct 3, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Product Attachment for WooCommerce plugin <= 2.1.8 versions.
Affected Software
1 affected component
MULTIDOTS Product Attachment For Woocommerce Wordpress<=2.1.8
Remediation
Information
Update to 2.2.0 or a higher version.
Event History
Oct 3, 2023
CVE Published
via MITRE·12:36 PM
Data Sourced
via MITRE·12:36 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-40212?
The severity of CVE-2023-40212 is medium with a CVSS score of 6.5.
2
How does the Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Product Attachment for WooCommerce plugin (CVE-2023-40212) work?
The CSRF vulnerability allows an attacker to trick a user into performing unwanted actions on a website where the victim is authenticated.
3
Which versions of theDotstore Product Attachment for WooCommerce plugin are affected by CVE-2023-40212?
Versions up to and including 2.1.8 of theDotstore Product Attachment for WooCommerce plugin are affected by CVE-2023-40212.
4
Is there a patch or fix available for CVE-2023-40212?
Yes, a patch is available for CVE-2023-40212. It is recommended to update to a version beyond 2.1.8 to fix the vulnerability.
5
Where can I find more information about CVE-2023-40212?
You can find more information about CVE-2023-40212 on the Patchstack website.