HIGH
Dotstore
CVE published 2026-04-08
CVE-2026-39671
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Extra Fees Plugin for WooCommerce, affecting versions from n/a through <= 4.3.3. This issue allows attackers to perform Cross Site Request Forgery. The vulnerability has a high impact due to its potential for tricking authenticated users into performing unintended actions. The Extra Fees Plugin for WooCommerce is used for adding extra fees du [truncated]