Unprotected CSRF Vulnerability in WP-Cart for Digital Products
CVE-2024-6075
8.8HIGH
What is CVE-2024-6075?
The wp-cart-for-digital-products plugin for WordPress, prior to version 8.5.5, is susceptible to Cross-Site Request Forgery (CSRF) vulnerabilities due to inadequate CSRF checks in certain functionalities. This flaw permits attackers to exploit logged-in users’ sessions to execute unauthorized actions, undermining the integrity and security of the affected WordPress sites. It is crucial for users of this plugin to update to the latest version to mitigate potential risks associated with this vulnerability.