Cross-Site Request Forgery (CSRF) Vulnerability in WooCommerce Upload My File
When it comes to hacking websites most of the time hackers are not interested in targeting specific websites, instead they are just trying to hit as many websites as possible to use for various purposes. That means that many types of vulnerabilites are not much of a threat because hackers are not often trying to exploit them. You still want to make sure those vulnerabilities don’t exist because if someone does target your website, you don’t want to be vulnerable. When it comes to WordPress websites, what seems like it would be one of the most interesting type of website to be the subject of targeted attacks would be website with eCommerce functionality, since there is sensitive data being handled by the website.
One of the more popular eCommerce solutions for WordPress is WooCommerce, which has over 1 million active installs according to wordpress.org (which includes this website). There are also many plugins designed to work with that and each of those things introduces additional security risks. Since we started this service quite a few of those plugins have been found to have security vulnerabilities. We just came across another one. [Read more]