The WP eCommerce plugin through version 3.15.1 is vulnerable to cross-site request forgery (CSRF) attacks due to the absence of CSRF checks when deleting coupons. This enables potential attackers to trick an authenticated admin into inadvertently deleting coupons.
We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.