First published: Fri Dec 27 2024(Updated: )
The DN Shipping by Weight for WooCommerce WordPress plugin before 1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
WooCommerce DN Shipping by Weight | <1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-11842 has a medium severity rating due to its potential for exploitation via CSRF attacks.
To fix CVE-2024-11842, update the DN Shipping by Weight for WooCommerce plugin to version 1.2 or higher.
CVE-2024-11842 enables attackers to perform Cross-Site Request Forgery (CSRF) attacks on the plugin's settings.
CVE-2024-11842 affects users of the DN Shipping by Weight for WooCommerce plugin versions prior to 1.2.
As of now, there are no publicly available exploits specifically targeting CVE-2024-11842.