{“error”:0,”message”:null,”data”:{“name”:”Facebook for WooCommerce”,”plugin”:”facebook-for-woocommerce”,”link”:”https:\/\/wordpress.org\/plugins\/facebook-for-woocommerce\/”,”latest”:”1760959320″,”closed”:0,”vulnerability”:[{“uuid”:”0563492a498fe859c1731f926edfdb92e989fecf4575b2f2b83226668d54bd29″,”name”:”Facebook for WooCommerce [facebook-for-woocommerce] < 1.9.15","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.9.15","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2019-15840","name":"CVE-2019-15840","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2019-15840","description":"[en] The facebook-for-woocommerce plugin before 1.9.14 for WordPress has CSRF.","date":"2019-08-30"},{"id":"dbbcccd7-533a-4ab7-af64-c86bf3e2b677","name":"Facebook for WooCommerce <= 1.9.12 – CSRF allowing Option Update","link":"https:\/\/wpscan.com\/vulnerability\/dbbcccd7-533a-4ab7-af64-c86bf3e2b677","description":"The original issue has been fixed via 1.9.14.\r\n\r\nHowever, as additional CSRF checks have been implemented in 1.9.15, the fixed in has been set to 1.9.15","date":null},{"id":"6a5df217d4a5852994fffc8483b8a58d8da384d7","name":"Facebook for WooCommerce <= 1.9.12 – Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/facebook-for-woocommerce\/facebook-for-woocommerce-1912-cross-site-request-forgery","description":"The facebook-for-woocommerce plugin before 1.9.14 for WordPress has CSRF.","date":"2019-06-18"}],"impact":{"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}]}},{"uuid":"becd1b63229bb89c88e61b57970d12c98ff4270dff86bdb246e9db1c714aa907","name":"Facebook for WooCommerce [facebook-for-woocommerce] < 1.9.15","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.9.15","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2019-15841","name":"CVE-2019-15841","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2019-15841","description":"[en] The facebook-for-woocommerce plugin before 1.9.15 for WordPress has CSRF via ajax_woo_infobanner_post_click, ajax_woo_infobanner_post_xout, or ajax_fb_toggle_visibility.","date":"2019-08-30"},{"id":"3fdd07a89834b3c5a767f93793a7744de3803e04","name":"Facebook for WooCommerce <= 1.9.12 – Cross-Site Request Forgery allowing Option Update","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/facebook-for-woocommerce\/facebook-for-woocommerce-1912-cross-site-request-forgery-allowing-option-update","description":"The facebook-for-woocommerce plugin before 1.9.15 for WordPress has CSRF via ajax_woo_infobanner_post_click, ajax_woo_infobanner_post_xout, or ajax_fb_toggle_visibility.","date":"2019-06-18"}],"impact":{"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}]}},{"uuid":"87357544cd31126dafbf781db6823a91d64c7405f4cc6800a3da7389da8100a3","name":"Facebook for WooCommerce [facebook-for-woocommerce] < 1.9.14","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.9.14","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"abf506a08f48a76630ff031f29aa4dbfb05c5567","name":"WordPress Facebook for WooCommerce plugin <= 1.9.12 – Cross-Site Request Forgery (CSRF) vulnerability allowing Option Update","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/facebook-for-woocommerce\/vulnerability\/wordpress-facebook-for-woocommerce-plugin-1-9-12-cross-site-request-forgery-csrf-vulnerability-allowing-option-update","description":"Cross-Site Request Forgery (CSRF) vulnerability allowing Option Update found in WordPress Facebook for WooCommerce plugin (versions <= 1.9.12).","date":"2019-06-25"}],"impact":[]},{"uuid":"846c051227d42782095ad20bf31eed633b62f7f1b414a56f1d151567bea26fb5","name":"Facebook for WooCommerce [facebook-for-woocommerce] < 3.5.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.5.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-64296","name":"CVE-2025-64296","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-64296","description":"","date":null}],"impact":[]}]},"updated":"1761729077"}