cleantalk
Vulnerabilities and Security Researches

Product Category Slider for WooCommerce, c475256758618c5134272f2b2ef2e2716df75491

Published on
Mar 21, 2023
Research Description
Product Category Slider for WooCommerce [woo-category-slider-by-pluginever] < 4.1.6 WordPress Product Category Slider for WooCommerce Plugin <= 4.1.5 is vulnerable to Cross Site Request Forgery (CSRF) No patched version is available. No reply from the vendor. Lana Codes discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Product Category Slider for WooCommerce Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has not been known to be fixed yet.
Affected versions
max 4.1.6.
Status
vulnerable