CVE-2023-41858

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Oct 10, 2023
Updated: Oct 12, 2023
CWE ID 352

Summary

CVE-2023-41858 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Ashok Rane Order Delivery Date plugin for WP e-Commerce versions 1.2 and below. This issue allows malicious actors to manipulate a user's session and submit unintended actions on their behalf. As a result, attackers could alter order details or even make unauthorized transactions, posing a significant risk to e-commerce sites using the vulnerable plugin. To mitigate this threat, users are strongly encouraged to update to the latest version of WP e-Commerce or consider alternative plugins for managing order delivery dates.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share