PatchSiren cyber security CVE debrief
CVE-2026-39671 Dotstore CVE debrief
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Extra Fees Plugin for WooCommerce, affecting versions from n/a through <= 4.3.3. This issue allows attackers to perform Cross Site Request Forgery. The vulnerability has a high impact due to its potential for tricking authenticated users into performing unintended actions. The Extra Fees Plugin for WooCommerce is used for adding extra fees during checkout and does not properly validate requests, which could lead to unauthorized actions on behalf of the user. Users should verify the legitimacy of requests to prevent exploitation. The CVE record was published on 2026-04-08T09:16:38.553Z and was last modified on 2026-07-24T20:10:00.147Z. The NVD entry is currently Deferred.
- Vendor
- Dotstore
- Product
- Extra Fees Plugin for WooCommerce
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-08
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-08
- Advisory updated
- 2026-07-24
Who should care
Users of Extra Fees Plugin for WooCommerce, particularly those with untrusted users accessing the plugin's functionality, should be aware of this vulnerability. Operators, administrators, and security teams responsible for the plugin's deployment should review and mitigate this vulnerability.
Technical summary
The Extra Fees Plugin for WooCommerce has a Cross-Site Request Forgery (CSRF) vulnerability. The plugin, used for adding extra fees during checkout, does not properly validate requests, allowing an attacker to trick authenticated users into performing unintended actions. This could lead to unauthorized actions on behalf of the user. The vulnerability has a high impact due to its potential for significant effects through Cross Site Request Forgery. Operators and administrators should review and mitigate this vulnerability. The issue affects versions from n/a through <= 4.3.3, and updating to version 4.3.4 or higher is recommended if available.
Defensive priority
High priority due to the potential for significant impact through Cross Site Request Forgery.
Recommended defensive actions
- Inventory and verify the version of Extra Fees Plugin for WooCommerce in use.
- Apply the latest patch or update to version 4.3.4 or higher if available.
- Implement compensating controls such as monitoring for suspicious activity.
- Educate users about the risks of CSRF and the importance of verifying request legitimacy.
- Review and update security configurations to prevent similar vulnerabilities.
- Monitor for potential exploitation attempts and adjust defenses accordingly.
- Perform a thorough review of the plugin's integration with other systems for potential vulnerabilities.
Evidence notes
The CVE record was published on 2026-04-08T09:16:38.553Z and was last modified on 2026-07-24T20:10:00.147Z. The NVD entry is currently Deferred. Evidence is limited to CVE and NVD information. Defenders should verify the affected product scope and vendor guidance.
Official resources
-
CVE-2026-39671 CVE record
CVE.org
-
CVE-2026-39671 NVD detail
NVD
-
Source item URL
nvd_modified
- Mitigation or vendor reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-08T09:16:38.553Z and has not been modified since then. The NVD entry is currently Deferred.