CVE · Medium

CVE-2021-4393 — eCommerce Product Catalog [ecommerce-product-catalog] < 3.0.18

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-4393 eCommerce Product Catalog [ecommerce-product-catalog] < 3.0.18 Cross-Site Request Forgery (CSRF) Medium 4.3 < 3.0.18 3.0.18 2021-03-01

CVE-2021-4393

The eCommerce Product Catalog Plugin for WordPress contains a Cross-Site Request Forgery vulnerability affecting versions 3.0.17 and earlier because the save() function fails to properly implement nonce verification. An attacker can exploit this flaw by crafting a malicious request that, if clicked by an administrator, allows unauthorized creation of manual digital orders on the affected site. The vulnerability requires social engineering to succeed but poses a significant risk to order integrity and site security.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.