Impact
Unauthenticated Cross Site Request Forgery (CSRF) exists in the Persian WooCommerce Shipping plugin version 4.4.5 or earlier, allowing an attacker to trigger privileged operations without proper authentication. Based on the description, it is inferred that a crafted request could alter shipping settings, place unauthorized orders, or perform other actions that normally require administrative permissions. This flaw constitutes the common weakness CWE‑352 and can lead to unauthorized data manipulation or service disruption.
Affected Systems
The affected component is the WordPress Persian WooCommerce Shipping plugin developed by Mahdi Yousefi. Any WordPress site running version 4.4.5 or earlier is vulnerable and at risk of CSRF exploitation.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation currently. The vulnerability is not listed in CISA KEV, implying it is not widely exploited yet. Based on the description, it is inferred that attackers can target any user, including unauthenticated visitors, by sending a maliciously crafted request that triggers privileged actions without needing authentication.
OpenCVE Enrichment