{ "id": "CVE-2023-3507", "sourceIdentifier": "contact@wpscan.com", "published": "2023-07-31T10:15:10.847", "lastModified": "2023-07-31T10:15:10.847", "vulnStatus": "Received", "descriptions": [ { "lang": "en", "value": "The WooCommerce Pre-Orders WordPress plugin before 2.0.3 has a flawed CSRF check when canceling pre-orders, which could allow attackers to make logged in admins cancel arbitrary pre-orders via a CSRF attack" } ], "metrics": {}, "weaknesses": [ { "source": "contact@wpscan.com", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-352" } ] } ], "references": [ { "url": "https://wpscan.com/vulnerability/e72bbe9b-e51d-40ab-820d-404e0cb86ee6", "source": "contact@wpscan.com" } ] }