Cross-Site Request Forgery Vulnerability in eCommerce Product Catalog Plugin for WordPress
CVE-2024-12771

8.8HIGH

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
21 December 2024

Summary

CVE-2024-12771 is a critical Cross-Site Request Forgery (CSRF) vulnerability found in the eCommerce Product Catalog Plugin for WordPress, applicable to all versions up to and including 3.3.43. This vulnerability arises from inadequate nonce validation in the 'customer_panel_password_reset' function, allowing unauthenticated attackers to reset passwords for any administrator or customer account. By deceiving a site administrator into clicking on a malicious link, attackers can exploit this flaw to execute unauthorized actions, posing significant risks to system integrity and user security.

Affected Version(s)

eCommerce Product Catalog Plugin for WordPress * <= 3.3.43

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Khayal Farzaliyev
.