CVE-2024-24837

MEDIUM

FG PrestaShop to WooCommerce <4.44.3 - CSRF

Title source: llm
STIX 2.1

Description

Cross-Site Request Forgery (CSRF) vulnerability in Frédéric GILLES FG PrestaShop to WooCommerce, Frédéric GILLES FG Drupal to WordPress, Frédéric GILLES FG Joomla to WordPress.This issue affects FG PrestaShop to WooCommerce: from n/a through 4.44.3; FG Drupal to WordPress: from n/a through 3.67.0; FG Joomla to WordPress: from n/a through 4.15.0.

Scores

CVSS v3 4.3
EPSS 0.0028
EPSS Percentile 19.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-352
Status published
Products (3)
Frédéric GILLES/FG Drupal to WordPress < 3.67.0
Frédéric GILLES/FG Joomla to WordPress < 4.15.0
Frédéric GILLES/FG PrestaShop to WooCommerce < 4.44.3
Published Feb 21, 2024
Tracked Since Feb 18, 2026