WooCommerce AJAX Product Filters <= 1.3.6 - Arbitrary Settings Update

2019-09-18 00:00
Sucuri Research Team

Strategic Overview

Status
Patched in 1.3.7
Affected Version< 1.3.7
CVSS8.3High
CVEN/A
View all Advanced AJAX Product Filters vulnerabilities

Vulnerability Overview

The WooCommerce AJAX Product Filters plugin for WordPress is vulnerable to Arbitrary Settings Update in versions up to, and including, 1.3.6. This is due to incorrect usage of the admin_init hook. This makes it possible for unauthenticated attackers to change any of the plugin settings and redirect users to malicious URLs.

Technical Analysis

REMEDIATION: Update to version 1.3.7, or a newer patched version --- IDENTIFIER: CWE-269 (Improper Privilege Management) The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C