Описание
The WooCommerce WordPress plugin from versions 5.4.0 to 10.5.2 does not properly handle batch requests, which could allow unauthenticated users to make a logged in admin call non store/WC REST endpoints, and create arbitrary admin users via a CSRF attack for example.
EPSS
Процентиль: 3%
0.00126
Низкий
7.5 High
CVSS3
Дефекты
CWE-352
Связанные уязвимости
CVSS3: 7.5
github
5 месяцев назад
The WooCommerce WordPress plugin from versions 5.4.0 to 10.5.2 does not properly handle batch requests, which could allow unauthenticated users to make a logged in admin call non store/WC REST endpoints, and create arbitrary admin users via a CSRF attack for example.
EPSS
Процентиль: 3%
0.00126
Низкий
7.5 High
CVSS3
Дефекты
CWE-352