The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.9. This is due to missing or incorrect nonce validation on the processBulkAction function. This makes it possible for unauthenticated attackers to delete pages and posts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Metrics
Affected Vendors & Products
References
History
Thu, 03 Apr 2025 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Cozyvision
Cozyvision sms Alert Order Notifications |
|
Weaknesses | CWE-352 | |
CPEs | cpe:2.3:a:cozyvision:sms_alert_order_notifications:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Cozyvision
Cozyvision sms Alert Order Notifications |

Status: PUBLISHED
Assigner: Wordfence
Published: 2024-03-13T15:27:22.170Z
Updated: 2024-08-02T19:29:14.034Z
Reserved: 2024-02-14T14:35:22.403Z
Link: CVE-2024-1489

Updated: 2024-08-02T19:29:10.950Z

Status : Analyzed
Published: 2024-03-13T16:15:23.377
Modified: 2025-04-03T13:13:02.067
Link: CVE-2024-1489

No data.