Cross-Site Request Forgery in WooCommerce Stock Manager WordPress Plugin
CVE-2021-34619

8.8HIGH

Key Information:

Vendor

Wordpress

Vendor
CVE Published:
21 July 2021

What is CVE-2021-34619?

The WooCommerce Stock Manager WordPress plugin is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Upload in versions up to, and including, 2.5.7 due to missing nonce and file validation in the /woocommerce-stock-manager/trunk/admin/views/import-export.php file.

Affected Version(s)

WooCommerce Stock Manager 2.5.7

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Chloe Chamberland, Wordfence
.