Cross-Site Request Forgery Vulnerability in Woo Commerce Minimum Weight Plugin for WordPress
CVE-2026-6932
4.3MEDIUM
What is CVE-2026-6932?
The Woo Commerce Minimum Weight plugin for WordPress is affected by a Cross-Site Request Forgery vulnerability, which is present in all versions up to and including 3.0.1. This vulnerability stems from a lack of nonce verification on the settings update handler in the edit-weight.php file. As a result, unauthenticated attackers can potentially manipulate the minimum order weight setting by deceiving a site administrator into engaging with a malicious link or by accessing an attacker-controlled webpage that sends a forged POST request. Mitigation of this risk requires immediate attention to update the plugin and ensure nonce verification is properly implemented.
Affected Version(s)
Woo Commerce Minimum Weight 0 <= 3.0.1