CVE · Medium

CVE-2020-36743 — Product Catalog Simple [post-type-x] < 1.5.13

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2020-36743 Product Catalog Simple [post-type-x] < 1.5.13 Cross-Site Request Forgery (CSRF) Medium 4.3 < 1.5.13 1.5.13 2020-09-16

CVE-2020-36743

The Product Catalog Simple plugin versions 1.5.13 and earlier are susceptible to cross-site request forgery attacks because the implecode_save_products_meta() function does not properly validate nonces. An attacker could exploit this vulnerability by crafting a malicious request that, if clicked by an administrator, would allow the attacker to modify product metadata without proper authorization. Since nonce verification is absent or inadequate, unauthenticated users can perform these unauthorized actions.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.