plugin

Woo Esto Vulnerabilities

1 known security issue reported for the Woo Esto WordPress plugin. Most recent disclosed Sep 27, 2023.

1 medium

Running Woo Esto on your site? Check whether your installed version is affected.

Scan your site free

Woocommerce ESTO <= 2.23.1 - Cross-Site Request Forgery via saveSetting

medium

The Woocommerce ESTO plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.23.1. This is due to missing or incorrect nonce validation on the saveSetting function. This makes it possible for unauthenticated attackers to modify plugin settings via a forged request granted th...

CVSS:
4.3
Affected:
up to 2.23.1
Fixed in:
2.23.2
Disclosed:
Sep 27, 2023

CVE-2023-44260 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database