Fancy Product Designer <= 4.6.9 - Insufficient Authorization on Mulitple AJAX Actions

2023-04-05 00:00
Ram

Strategic Overview

Status
Patched in 4.7.0
Affected PluginFancy Product Designer
Affected Version<= 4.6.9
CVSS6.3Medium
CVECVE-2021-4335
View all Fancy Product Designer vulnerabilities

Vulnerability Overview

The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized access to data and modification of plugin settings due to a missing capability check on multiple AJAX functions in versions up to, and including, 4.6.9. This makes it possible for authenticated attackers with subscriber-level permissions to modify plugin settings, including retrieving arbitrary order information or creating/updating/deleting products, orders, or other sensitive information not associated with their own account.

Technical Analysis

REMEDIATION: Update to version 4.7.0, or a newer patched version --- IDENTIFIER: CWE-285 (Improper Authorization) The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C