CVE-2023-41686: WordPress Woocommerce Support System plugin <= 1.2.2 - Cross Site Request Forgery (CSRF) vulnerability
Published Dec 13, 2024
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in ilGhera Woocommerce Support System wc-support-system allows Cross Site Request Forgery.This issue affects Woocommerce Support System: from n/a through <= 1.2.2.
Affected Software
1 affected component
ilGhera Woocommerce Support System<=1.2.2
Remediation
Information
No patched version is available. No reply from the vendor
Event History
Dec 13, 2024
CVE Published
via MITRE·02:24 PM
Data Sourced
via MITRE·02:24 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-41686?
CVE-2023-41686 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
2
How does CVE-2023-41686 impact users of the ilGhera Woocommerce Support System?
CVE-2023-41686 allows attackers to perform unauthorized actions on behalf of a user without their consent.
3
What versions of the Woocommerce Support System are affected by CVE-2023-41686?
CVE-2023-41686 affects all versions up to and including 1.2.2 of the Woocommerce Support System.
4
How do I fix CVE-2023-41686?
To fix CVE-2023-41686, you should update the Woocommerce Support System to the latest version beyond 1.2.2.
5
Is CVE-2023-41686 a common vulnerability?
CSRF vulnerabilities like CVE-2023-41686 are common in web applications that fail to properly validate requests.