PT-2025-50814 · Markutos987+1 · Filter Plus – Product Filter & Wordpress Filter+2
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Product Filtering by Categories, Tags, Price Range for WooCommerce – Filter Plus versions prior to 1.1.7
Description
Unauthenticated attackers can modify plugin settings and create arbitrary filter options. This is caused by a missing capability check on the 'filter save settings' and 'add filter options' AJAX actions, which are used to process asynchronous requests to the server without reloading the page.
Recommendations
Update the plugin to a version later than 1.1.6.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Filter Plus – Product Filter & Wordpress Filter
Product Filtering By Categories
Filter-Plus