CVE-2023-41858
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2023-41858 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Ashok Rane Order Delivery Date plugin for WP e-Commerce versions 1.2 and below. This issue allows malicious actors to manipulate a user's session and submit unintended actions on their behalf. As a result, attackers could alter order details or even make unauthorized transactions, posing a significant risk to e-commerce sites using the vulnerable plugin. To mitigate this threat, users are strongly encouraged to update to the latest version of WP e-Commerce or consider alternative plugins for managing order delivery dates.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.