CVE-2020-36748
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Jul 1, 2023
Updated: Nov 7, 2023
Summary
CVE-2020-36748 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Dokan plugin for WordPress. Versions up to and including 3.0.8 are impacted. The handle_order_export() function lacks proper nonce validation, allowing unauthenticated attackers to trigger an order export through a forged request. Successful exploitation requires an administrator to perform a certain action, such as clicking on a malicious link.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- weDevs