Cross-Site Request Forgery Vulnerability in Automattic WooCommerce Plugin
CVE-2023-52222
4.3MEDIUM
What is CVE-2023-52222?
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Automattic WooCommerce plugin, impacting versions from n/a up to 8.2.2. This vulnerability could allow an attacker to perform unauthorized actions on behalf of users without their consent, potentially leading to severe consequences including data manipulation or unauthorized access to sensitive information. Users and administrators of WooCommerce are advised to review their installations and apply necessary security measures to mitigate the risks associated with this vulnerability.
Affected Version(s)
WooCommerce <= 8.2.2
