The URL Shortener | Conversion Tracking | AB Testing | WooCommerce WordPress plugin through 9.0.2 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting customers via CSRF attacks
Metrics
Affected Vendors & Products
References
History
Wed, 21 May 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Tahminajannat
Tahminajannat url Shortener \| Conversion Tracking \| Ab Testing \| Woocommerce |
|
Weaknesses | CWE-352 | |
CPEs | cpe:2.3:a:tahminajannat:url_shortener_\|_conversion_tracking_\|_ab_testing_\|_woocommerce:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Tahminajannat
Tahminajannat url Shortener \| Conversion Tracking \| Ab Testing \| Woocommerce |
Tue, 11 Mar 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Sun, 09 Mar 2025 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The URL Shortener | Conversion Tracking | AB Testing | WooCommerce WordPress plugin through 9.0.2 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting customers via CSRF attacks | |
Title | easy-broken-link-checker <= 9.0.2 - Bulk Actions via CSRF | |
References |
|

Status: PUBLISHED
Assigner: WPScan
Published: 2025-03-09T06:00:04.051Z
Updated: 2025-03-11T19:21:38.686Z
Reserved: 2025-02-16T04:03:48.954Z
Link: CVE-2025-1362

Updated: 2025-03-11T19:21:34.143Z

Status : Analyzed
Published: 2025-03-09T06:15:10.323
Modified: 2025-05-21T16:59:38.977
Link: CVE-2025-1362

No data.