CVE-2021-34619: Cross-Site Request Forgery in WooCommerce Stock Manager WordPress Plugin
Published Jul 21, 2021
·Updated
The WooCommerce Stock Manager WordPress plugin is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Upload in versions up to, and including, 2.5.7 due to missing nonce and file validation in the /woocommerce-stock-manager/trunk/admin/views/import-export.php file.
Affected Software
1 affected component
StoreApps Stock Manager For Woocommerce Wordpress<=2.5.7
Remediation
Information
Update to version 2.6.0.
Event History
Jul 21, 2021
CVE Published
via MITRE·11:09 AM
Data Sourced
via MITRE·11:09 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for the WooCommerce Stock Manager WordPress plugin?
The vulnerability ID for the WooCommerce Stock Manager WordPress plugin is CVE-2021-34619.
2
What is the severity rating of CVE-2021-34619?
The severity rating of CVE-2021-34619 is high with a score of 8.8.
3
What is the affected software version of CVE-2021-34619?
The affected software version of CVE-2021-34619 is up to and including 2.5.7.
4
What is the CWE ID for CVE-2021-34619?
The CWE ID for CVE-2021-34619 is CWE-352 and CWE-434.
5
How can I fix the vulnerability in the WooCommerce Stock Manager WordPress plugin?
To fix the vulnerability in the WooCommerce Stock Manager WordPress plugin, update to a version beyond 2.5.7.