Cross-Site Request Forgery Vulnerability in Abandoned Cart Lite for WooCommerce by WordPress
CVE-2021-4414
4.3MEDIUM
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 12 July 2023
Summary
The Abandoned Cart Lite for WooCommerce plugin for WordPress is susceptible to Cross-Site Request Forgery due to inadequate nonce validation in the wcal_preview_emails() function. This flaw allows attackers to craft malicious requests, potentially tricking an administrator into executing actions that generate email preview templates without proper authentication. As users interact with the site, exploiting this vulnerability could lead to unauthorized actions, compromising the site's security and operational integrity.
Affected Version(s)
Abandoned Cart Lite for WooCommerce * <= 5.8.5
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jerome Bruandet