CyberRota Analysis
AI-GeneratedThe vulnerability allows unauthenticated Cross Site Request Forgery (CSRF) attacks in versions 4.4.5 and earlier of the WooCommerce shipping plugin, potentially enabling attackers to perform unauthorized actions on behalf of users. This could lead to unauthorized modifications to shipping settings or orders, impacting the integrity of e-commerce operations. Organizations using this plugin should prioritize remediation to protect against potential exploitation.
CVE
CVE-2026-65536
Severity
MEDIUM
CVSS
6.5
EPSS
0.12%
Original NVD Description
Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions.