Mautic Integration for WooCommerce < 1.0.3 - Cross-Site Request Forgery leading to Arbitrary Options Update
mediumThe Mautic Integration for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, but not including, 1.0.3. This is due to missing or incorrect nonce validation when updating plugin settings. Further, the options being updated are not checked properly to restrict them to the pl...
- CVSS:
- 4.3
- Affected:
- up to 1.0.3
- Fixed in:
- 1.0.3
- Disclosed:
- Dec 20, 2022