Sceawere

Vulnerability Detail

CVE-2026-96838UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated CSRF in Blacklist Manager

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
3h ago
Vendor
YoOhw Studio
Product
Blacklist Manager – WooCommerce Anti-Fraud, Blacklist & Checkout Verification
Attack Type
CWE-352 Cross-Site Request Forgery (CSRF)
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Cross Site Request Forgery (CSRF) in Blacklist Manager &#8211; WooCommerce Anti-Fraud, Blacklist &amp; Checkout Verification <= 2.3.1 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-09-30T13:17:33.810Z",
  "pubdate": "2026-09-30T13:17:33.810Z",
  "executiveSummary": "The Blacklist Manager – WooCommerce Anti-Fraud, Blacklist & Checkout Verification plugin, in versions 2.3.1 and earlier, is susceptible to an unauthenticated Cross-Site Request Forgery (CSRF) vulnerability.\nThis security flaw arises due to the absence of adequate nonce verification or equivalent anti-CSRF tokens within the plugin's administrative or settings-related request handlers.\nThe vulnerability allows a remote, unauthenticated attacker to trick a logged-in administrator into executing unintended state-changing actions via a specially crafted web request.\nSuccessful exploitation enables unauthorized modifications to plugin configurations, such as altering blacklist parameters or disabling security features, potentially compromising the integrity of the checkout verification process.\nThe impact is significant, as it permits attackers to manipulate the fraud protection mechanisms of a WooCommerce site without requiring direct credentials, provided they can entice an authenticated administrative user to perform an action.\nRisk implications include the potential for bypassing anti-fraud logic, facilitating malicious transactions, or weakening the overall security posture of the e-commerce environment.",
  "technicalDetails": "The vulnerability is rooted in the plugin's failure to implement proper CSRF protection mechanisms for critical administrative actions. In WordPress development, nonce verification is the standard defense against CSRF; the affected versions lack this implementation for specific request endpoints, rendering them exposed.\nThe attack flow begins when an attacker crafts a malicious request—typically via a hidden HTML form or an injected script—targeting the plugin's administrative functionality. This request is designed to mimic legitimate administrative actions, such as saving settings or updating the blacklist database.\nThe attacker must entice an authenticated administrator to interact with a malicious resource or visit a compromised site while logged into the WordPress dashboard. Once the administrator triggers the request, the browser automatically includes the administrator's session cookies with the request.\nBecause the server-side code does not validate the integrity or the origin of the request using a nonce, it treats the incoming request as a legitimate instruction from the administrator. The plugin's back-end component executes the specified function, allowing the attacker to perform unauthorized actions such as disabling fraud detection rules, removing blacklist entries, or injecting malicious configuration data.\nAffected versions include 2.3.1 and all versions prior. The vulnerability does not require prior authentication by the attacker, relying solely on the existence of an active administrative session. The network exposure is broad, as the attack can be delivered through any web-based vector including social engineering, phishing, or cross-site scripting (XSS) on third-party domains.\nPost-exploitation, an attacker can manipulate the plugin's behavior to facilitate fraudulent checkout activities. By removing IPs or email addresses from the blacklist, or by altering the verification workflow, the attacker effectively neutralizes the anti-fraud measures the plugin was intended to provide. This manipulation often goes unnoticed as the malicious changes are attributed to the legitimate administrator."
}
CVE-2026-96838: Unauthenticated CSRF in Blacklist Manager (HIGH Severity, CVSS: 8.8) | Sceawere