CVE-2023-40559: WordPress WooCommerce Dynamic Pricing and Discount Rules Plugin <= 2.4.0 is vulnerable to Cross Site Request Forgery (CSRF)
Published Oct 4, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Dynamic Pricing and Discount Rules for WooCommerce plugin <= 2.4.0 versions.
Affected Software
1 affected component
MULTIDOTS Dynamic Pricing And Discount Rules For Woocommerce Wordpress<2.4.1
Remediation
Information
Update to 2.4.1 or a higher version.
Event History
Oct 4, 2023
CVE Published
via MITRE·02:11 PM
Data Sourced
via MITRE·02:11 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-40559?
The severity of CVE-2023-40559 is high.
2
What is the affected software of CVE-2023-40559?
The affected software of CVE-2023-40559 is the Multidots Dynamic Pricing And Discount Rules For Woocommerce plugin version <= 2.4.0.
3
How does CVE-2023-40559 affect WordPress?
CVE-2023-40559 affects WordPress through the Multidots Dynamic Pricing And Discount Rules For Woocommerce plugin version <= 2.4.0.
4
How can I fix CVE-2023-40559?
To fix CVE-2023-40559, update the Multidots Dynamic Pricing And Discount Rules For Woocommerce plugin to version 2.4.1 or newer.
5
What is the CWE of CVE-2023-40559?
The CWE of CVE-2023-40559 is CWE-352 (Cross-Site Request Forgery).