Cross-Site Request Forgery Vulnerability in eCommerce Product Catalog Plugin for WordPress
CVE-2024-12771
8.8HIGH
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 21 December 2024
What is CVE-2024-12771?
CVE-2024-12771 is a critical Cross-Site Request Forgery (CSRF) vulnerability found in the eCommerce Product Catalog Plugin for WordPress, applicable to all versions up to and including 3.3.43. This vulnerability arises from inadequate nonce validation in the 'customer_panel_password_reset' function, allowing unauthenticated attackers to reset passwords for any administrator or customer account. By deceiving a site administrator into clicking on a malicious link, attackers can exploit this flaw to execute unauthorized actions, posing significant risks to system integrity and user security.
Affected Version(s)
eCommerce Product Catalog Plugin for WordPress * <= 3.3.43