ZeroHour

CVE-2024-2322

PoC
CVSS 3.1
6.8 medium
EPSS
<1%p29
Published
()
Modified
Description

The WooCommerce Cart Abandonment Recovery WordPress plugin before 1.2.27 does not have CSRF check in its bulk actions, which could allow attackers to make logged in admins delete arbitrary email templates as well as delete and unsubscribe users from abandoned orders via CSRF attacks.

Vendors
cartflows
Products
woocommerce cart abandonment recovery
Ecosystems
WordPress, E-commerce
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.