WordPress Thank You Page Customizer for WooCommerce – Increase Your Sales Plugin <= 1.0.13 is vulnerable to Cross Site Request Forgery (CSRF)
CVE-2022-46812
8.8HIGH
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 25 May 2023
Summary
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in VillaTheme's Thank You Page Customizer for WooCommerce versions up to 1.0.13. This weakness allows an attacker to trick an authenticated user into unknowingly executing actions against the WooCommerce store, potentially compromising user data and leading to unauthorized changes. Users of the affected plugin should promptly review their security posture and ensure that they are using the latest version to mitigate exposure to this vulnerability.
Affected Version(s)
Thank You Page Customizer for WooCommerce – Increase Your Sales <= 1.0.13
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Cat (Patchstack Alliance)