FastPicker
- <= 1.0.2
A Cross-Site Request Forgery (CSRF) vulnerability exists in the FastPicker WordPress plugin, specifically in the order management system for WooCommerce. This vulnerability affects all versions up to and including 1.0.2. The issue arises from inadequate nonce validation in the 'settingsPage' function, allowing unauthenticated attackers to manipulate the plugin's settings. Exploitation requires tricking a site administrator into clicking a link that initiates the forged request, which could toggle webhook integration or alter API URLs.
Exploitation of this vulnerability could lead to unauthorized changes in the plugin's settings, including webhook integration and API URL modifications.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.