Executive brief
The Woo Commerce Minimum Weight plugin for WordPress, which allows store owners to set minimum weight requirements for orders, contains a security flaw. An attacker could trick a site administrator into clicking a malicious link, allowing the attacker to change the store's minimum order weight settings without authorization. This could disrupt normal checkout processes or interfere with shipping rules.
Technical details
The Woo Commerce Minimum Weight plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) due to missing nonce verification on the settings update handler in the edit-weight.php file. This vulnerability affects all versions up to and including 3.0.1. An unauthenticated attacker can exploit this by crafting a forged POST request and tricking a logged-in administrator into submitting it, typically via social engineering or a malicious website. Successful exploitation allows the attacker to modify the 'minimum order weight' configuration setting. As of the advisory date, users should ensure they are looking for updates beyond version 3.0.1.
Affected products
- Woo Commerce Minimum Weight Woo Commerce Minimum Weight up to and including 3.0.1
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory
References
- https://plugins.trac.wordpress.org/browser/woo-commerce-min-weight/tags/3.0.1/edit-weight.php
- https://plugins.trac.wordpress.org/browser/woo-commerce-min-weight/tags/3.0.1/edit-weight.php
- https://plugins.trac.wordpress.org/browser/woo-commerce-min-weight/trunk/edit-weight.php
- https://plugins.trac.wordpress.org/browser/woo-commerce-min-weight/trunk/edit-weight.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/b2c44c95-6a00-4c56-967b-003ce307f90c?source=cve