Description
Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions.
Published: 2026-07-23
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Unauthenticated Cross Site Request Forgery (CSRF) exists in the Persian WooCommerce Shipping plugin version 4.4.5 or earlier, allowing an attacker to trigger privileged operations without proper authentication. Based on the description, it is inferred that a crafted request could alter shipping settings, place unauthorized orders, or perform other actions that normally require administrative permissions. This flaw constitutes the common weakness CWE‑352 and can lead to unauthorized data manipulation or service disruption.

Affected Systems

The affected component is the WordPress Persian WooCommerce Shipping plugin developed by Mahdi Yousefi. Any WordPress site running version 4.4.5 or earlier is vulnerable and at risk of CSRF exploitation.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation currently. The vulnerability is not listed in CISA KEV, implying it is not widely exploited yet. Based on the description, it is inferred that attackers can target any user, including unauthenticated visitors, by sending a maliciously crafted request that triggers privileged actions without needing authentication.

Generated by OpenCVE AI on August 5, 2026 at 01:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Persian WooCommerce Shipping plugin to a version newer than 4.4.5 to eliminate the CSRF flaw
  • If an immediate update is not feasible, remove or disable the plugin until a patch is applied to prevent the vulnerability from being triggered
  • Monitor administrative activity logs for unauthorized order placements or configuration changes that may indicate exploitation

Generated by OpenCVE AI on August 5, 2026 at 01:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Mahdi Yousefi
Mahdi Yousefi افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری)
Wordpress
Wordpress wordpress
Vendors & Products Mahdi Yousefi
Mahdi Yousefi افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری)
Wordpress
Wordpress wordpress

Thu, 23 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions.
Title WordPress افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) plugin <= 4.4.5 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}


Subscriptions

Mahdi Yousefi افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری)
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T14:03:30.708Z

Reserved: 2026-07-22T08:54:12.816Z

Link: CVE-2026-65536

cve-icon Vulnrichment

Updated: 2026-07-23T14:03:27.560Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:18:46.617

Modified: 2026-07-23T14:17:59.933

Link: CVE-2026-65536

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T01:15:03Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)