Fancy Product Designer <= 4.6.9 - Insufficient Authorization to Arbitrary Options Update via fpd_update_options

2023-04-05 00:00
Ram

Strategic Overview

Status
Patched in 4.7.0
Affected PluginFancy Product Designer
Affected Version<= 4.6.9
CVSS8.8High
CVECVE-2021-4334
View all Fancy Product Designer vulnerabilities

Vulnerability Overview

The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized modification of site options due to a missing capability check on the fpd_update_options function in versions up to, and including, 4.6.9. This makes it possible for authenticated attackers with subscriber-level permissions to modify site options, including setting the default role to administrator which can allow privilege escalation.

Technical Analysis

REMEDIATION: Update to version 4.7.0, or a newer patched version --- IDENTIFIER: CWE-285 (Improper Authorization) The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C