PatchSiren cyber security CVE debrief
CVE-2026-39671 Dotstore CVE debrief
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Extra Fees Plugin for WooCommerce, affecting versions from n/a through <= 4.3.3. This issue allows attackers to perform Cross Site Request Forgery. The vulnerability has a high impact due to its potential for tricking authenticated users into performing unintended actions. The Extra Fees Plugin for WooCommerce is used for adding extra fees during checkout and does not properly validate requests, which could lead to unauthorized actions on behalf of the user. Users should verify the legitimacy of requests to prevent exploitation. The CVE record was published on 2026-04-08T09:16:38.553Z and was last modified on 2026-07-24T20:10:00.147Z. The NVD entry is currently Deferred.
- Vendor
- Dotstore
- Product
- Extra Fees Plugin for WooCommerce
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-08
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-08
- Advisory updated
- 2026-07-24
Who should care
Users of Extra Fees Plugin for WooCommerce, particularly those with untrusted users accessing the plugin's functionality, should be aware of this vulnerability. Operators, administrators, and security teams responsible for the plugin's deployment should review and mitigate this vulnerability.
Technical summary
The Extra Fees Plugin for WooCommerce has a Cross-Site Request Forgery (CSRF) vulnerability. The plugin, used for adding extra fees during checkout, does not properly validate requests, allowing an attacker to trick authenticated users into performing unintended actions. This could lead to unauthorized actions on behalf of the user. The vulnerability has a high impact due to its potential for significant effects through Cross Site Request Forgery. Operators and administrators should review and mitigate this vulnerability. The issue affects versions from n/a through <= 4.3.3, and updating to version 4.3.4 or higher is recommended if available.
Defensive priority
High priority due to the potential for significant impact through Cross Site Request Forgery.
Recommended defensive actions
- Inventory and verify the version of Extra Fees Plugin for WooCommerce in use.
- Apply the latest patch or update to version 4.3.4 or higher if available.
- Implement compensating controls such as monitoring for suspicious activity.
- Educate users about the risks of CSRF and the importance of verifying request legitimacy.
- Review and update security configurations to prevent similar vulnerabilities.
- Monitor for potential exploitation attempts and adjust defenses accordingly.
- Perform a thorough review of the plugin's integration with other systems for potential vulnerabilities.
Evidence notes
The CVE record was published on 2026-04-08T09:16:38.553Z and was last modified on 2026-07-24T20:10:00.147Z. The NVD entry is currently Deferred. Evidence is limited to CVE and NVD information. Defenders should verify the affected product scope and vendor guidance.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-39671 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-39671
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-39671 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-39671
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.