ShopEngine
cpe:2.3:a:wpmet:shopengine:*:*:*:*:wordpress:*:*
- <= 4.8.5
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the ShopEngine Elementor WooCommerce Builder Addon plugin for WordPress, affecting all versions through 4.8.5. The vulnerability arises from inadequate nonce validation in the 'post_add_to_list' function and a flawed permissions callback in the 'Api/init' function. This allows unauthenticated attackers to manipulate a user's wishlist by adding or removing products, provided they can deceive the user into clicking a link.
Exploitation of this vulnerability allows for unauthorized manipulation of a user's wishlist, enabling attackers to add or remove products without the user's consent.
Users are advised to update the ShopEngine Elementor WooCommerce Builder Addon plugin to version 4.8.6 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.