plugin

Advanced Free Flat Shipping Woocommerce Vulnerabilities

2 known security issues reported for the Advanced Free Flat Shipping Woocommerce WordPress plugin. Most recent disclosed Jul 11, 2023.

1 medium

Running Advanced Free Flat Shipping Woocommerce on your site? Check whether your installed version is affected.

Scan your site free

Flat rate shipping rates / Conditional shipping / Flexible shipping &#8211; WooCommerce shipping plugin [advanced-free-flat-shipping-woocommerce] < 1.6.4.6

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in PI Websolution Conditional shipping & Advanced Flat rate shipping rates / Flexible shipping for WooCommerce shipping plugin <= 1.6.4.4 versions.

Affected:
up to 1.6.4.6
Fixed in:
1.6.4.6
Disclosed:
Jul 11, 2023

CVE-2023-34015 on NVD →

Advanced Flat rate shipping Woocommerce <= 1.6.4.4 - Cross-Site Request Forgery via enableDisable and deletePost

medium

The Advanced Flat rate shipping Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.4.4. This is due to missing or incorrect nonce validation on the enableDisable and deletePost functions. This makes it possible for unauthenticated attackers to enable, disa...

CVSS:
4.3
Affected:
up to 1.6.4.4
Fixed in:
1.6.4.6
Disclosed:
Jun 2, 2023

CVE-2023-34015 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database