PT-2025-50814 · Markutos987+1 · Filter Plus – Product Filter & Wordpress Filter+2

·

CVE-2025-13314

·

Published

2025-12-11

·

Updated

2025-12-12

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Product Filtering by Categories, Tags, Price Range for WooCommerce – Filter Plus versions prior to 1.1.7
Description Unauthenticated attackers can modify plugin settings and create arbitrary filter options. This is caused by a missing capability check on the 'filter save settings' and 'add filter options' AJAX actions, which are used to process asynchronous requests to the server without reloading the page.
Recommendations Update the plugin to a version later than 1.1.6.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-13314

Affected Products

Filter Plus – Product Filter & Wordpress Filter
Product Filtering By Categories
Filter-Plus