Cross-Site Request Forgery Vulnerability in Abandoned Cart Lite for WooCommerce by WordPress
CVE-2021-4414

4.3MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
12 July 2023

Summary

The Abandoned Cart Lite for WooCommerce plugin for WordPress is susceptible to Cross-Site Request Forgery due to inadequate nonce validation in the wcal_preview_emails() function. This flaw allows attackers to craft malicious requests, potentially tricking an administrator into executing actions that generate email preview templates without proper authentication. As users interact with the site, exploiting this vulnerability could lead to unauthorized actions, compromising the site's security and operational integrity.

Affected Version(s)

Abandoned Cart Lite for WooCommerce * <= 5.8.5

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jerome Bruandet
.