CVE-2024-2843: WooCommerce Customers Manager < 30.1 - User Deletion via CSRF
The WooCommerce Customers Manager WordPress plugin before 30.1 does not have CSRF checks in some places, which could allow attackers to make logged in admin users delete users via CSRF attacks
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2843?
CVE-2024-2843 has a moderate severity rating due to its potential for CSRF attacks that could lead to unauthorized user deletions.
How do I fix CVE-2024-2843?
To fix CVE-2024-2843, upgrade the WooCommerce Customers Manager plugin to version 30.1 or later.
What type of attack is possible with CVE-2024-2843?
CVE-2024-2843 allows for Cross-Site Request Forgery (CSRF) attacks, enabling unauthorized actions by exploiting logged-in admin users.
Who is affected by CVE-2024-2843?
CVE-2024-2843 affects users of the WooCommerce Customers Manager WordPress plugin prior to version 30.1.
Is user data at risk with CVE-2024-2843?
Yes, user data could be at risk as attackers may delete user accounts through CSRF attacks if the vulnerability is exploited.