SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-65536

MEDIUM · CVSS 6.5 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

The vulnerability allows unauthenticated Cross Site Request Forgery (CSRF) attacks in versions 4.4.5 and earlier of the WooCommerce shipping plugin, potentially enabling attackers to perform unauthorized actions on behalf of users. This could lead to unauthorized modifications to shipping settings or orders, impacting the integrity of e-commerce operations. Organizations using this plugin should prioritize remediation to protect against potential exploitation.

CVE
CVE-2026-65536
Severity
MEDIUM
CVSS
6.5
EPSS
0.12%

Original NVD Description

Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions.