Flat rate shipping rates / Conditional shipping / Flexible shipping – WooCommerce shipping plugin [advanced-free-flat-shipping-woocommerce] < 1.6.4.6
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in PI Websolution Conditional shipping & Advanced Flat rate shipping rates / Flexible shipping for WooCommerce shipping plugin <= 1.6.4.4 versions.
- Affected:
- up to 1.6.4.6
- Fixed in:
- 1.6.4.6
- Disclosed:
- Jul 11, 2023
CVE-2023-34015 on NVD →
Advanced Flat rate shipping Woocommerce <= 1.6.4.4 - Cross-Site Request Forgery via enableDisable and deletePost
medium
The Advanced Flat rate shipping Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.4.4. This is due to missing or incorrect nonce validation on the enableDisable and deletePost functions. This makes it possible for unauthenticated attackers to enable, disa...
- CVSS:
- 4.3
- Affected:
- up to 1.6.4.4
- Fixed in:
- 1.6.4.6
- Disclosed:
- Jun 2, 2023
CVE-2023-34015 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database