CVE-2023-52127: WordPress WPC Product Bundles for WooCommerce Plugin <= 7.3.1 is vulnerable to Cross Site Request Forgery (CSRF)
Published Jan 5, 2024
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in WPClever WPC Product Bundles for WooCommerce.This issue affects WPC Product Bundles for WooCommerce: from n/a through 7.3.1.
Affected Software
1 affected component
WPClever Wpc Product Bundles For Woocommerce Wordpress<=7.3.1
Remediation
Information
Update to 7.3.2 or a higher version.
Event History
Jan 5, 2024
CVE Published
via MITRE·08:52 AM
Data Sourced
via MITRE·08:52 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-52127?
CVE-2023-52127 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2023-52127?
To remediate CVE-2023-52127, update the WPC Product Bundles for WooCommerce plugin to version 7.3.2 or later.
3
What versions of WPC Product Bundles for WooCommerce are affected by CVE-2023-52127?
CVE-2023-52127 affects WPC Product Bundles for WooCommerce versions up to and including 7.3.1.
4
Is CVE-2023-52127 a critical vulnerability?
CVE-2023-52127 may have significant security implications but does not have a common vulnerability scoring system rating indicating criticality available at this time.
5
What should I do if I cannot update WPC Product Bundles for WooCommerce for CVE-2023-52127?
If you cannot update, consider disabling the plugin temporarily and reviewing your site's security posture.