26 Aug 2019

Vulnerability Details: Cross-Site Request Forgery (CSRF) in WooCommerce Address Book

The changelog for the latest version of WooCommerce Address Book is “Security: Updated all save calls to do nonce verification checks.”. Looking at the changes made in that version we found that three AJAX accessible functions had nonce checks added to prevent cross-site request forgery (CSRF).


[Read more]