CyberRota Analysis
AI-GeneratedThe ShopEngine Elementor WooCommerce Builder Addon for WordPress prior to version 4.9.3 is vulnerable to Cross-Site Request Forgery (CSRF) due to inadequate protection on its authentication endpoint. This flaw allows an attacker to log victims into a malicious account, potentially compromising sensitive billing and shipping information entered during checkout. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this security risk.
Original NVD Description
The ShopEngine Elementor WooCommerce Builder Addon WordPress plugin before 4.9.3 does not protect one of its authentication endpoints against CSRF, allowing an attacker to log a victim into an attacker-controlled account, so that the billing and shipping details the victim then enters at checkout are stored under and readable by the attacker.