Cross-Site Request Forgery (CSRF)/Settings Change Vulnerability in Product Feed PRO for WooCommerce
The changelog for a recent version of the WordPress plugin Product Feed PRO for WooCommerce is:
…
The changelog for a recent version of the WordPress plugin Product Feed PRO for WooCommerce is:
…
As part of monitoring we do to make sure we are providing customers of our service with the best possible data on vulnerabilities in WordPress plugins they may use, we monitor for what look to be hackers probing for usage of plugins to make sure we quickly can warn our customers of unfixed vulnerabilities that hackers are likely targeting. There was probing on our website yesterday for the plugin Product Feed PRO for WooCommerce by requesting these files:
/wp-content/plugins/woo-product-feed-pro/css/woosea_admin.css
/wp-content/plugins/woo-product-feed-pro/js/woosea_add_cart.js
/wp-content/plugins/woo-product-feed-pro/readme.txt [Read more]