WordPress Plugin Vulnerabilities

WooCommerce Etsy Integration < 3.3.2 - Cross-Site Request Forgery

Description

The plugin does not correctly implement nonce validation in the etcpf_delete_feed() function, making it susceptible to Cross-Site Request Forgery. As a result, unauthenticated users may delete an export feed by duping an administrator into clicking on a malicious link.

Affects Plugins

References

Classification

Miscellaneous

Original Researcher
Jerome Bruandet
Verified
No

Timeline

Publicly Published
2021-08-16 (about 4 years ago)
Added
2023-07-12 (about 2 years ago)
Last Updated
2023-07-12 (about 2 years ago)

Other