PT-2026-65738 · WordPress · Facturación Electrónica Costa Rica
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Facturación Electrónica Costa Rica versions prior to 2.0.3
Description
The plugin is susceptible to Cross-Site Request Forgery (CSRF), a flaw where an attacker tricks a victim into performing actions they did not intend to do. This occurs due to missing or incorrect nonce validation within the (global scope, included by
fvcr admin page html) function. Unauthenticated attackers can exploit this to modify plugin configurations via forged requests, provided they can induce a site administrator to click a malicious link. Affected settings include API tokens, access tokens, economic activity, Hacienda environment mode, invoice and ticket emission flags, exchange rate, and branch settings.Recommendations
Update the plugin to a version newer than 2.0.2.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Facturación Electrónica Costa Rica