CVE-2024-29093
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2024-29093 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Tobias Conrad Builder for WooCommerce reviews shortcodes, specifically the ReviewShort component. This issue allows unauthenticated attackers to manipulate user actions, such as creating, editing, or deleting reviews, on affected websites. The vulnerability can be exploited by tricking a user into visiting a specially crafted malicious website. Affected versions of Builder for WooCommerce reviews shortcodes range from not available to 1.01.3. It is strongly recommended that users upgrade to a patched version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.