WooCommerce AJAX Product Filters <= 1.3.6 - Arbitrary Settings Update
2019-09-18 00:00
Sucuri Research TeamStrategic Overview
StatusPatched in 1.3.7
Affected PluginAdvanced AJAX Product Filters
Affected Version
< 1.3.7CVSS8.3High
CVE
N/AVulnerability Overview
The WooCommerce AJAX Product Filters plugin for WordPress is vulnerable to Arbitrary Settings Update in versions up to, and including, 1.3.6. This is due to incorrect usage of the admin_init hook. This makes it possible for unauthenticated attackers to change any of the plugin settings and redirect users to malicious URLs.
Technical Analysis
REMEDIATION: Update to version 1.3.7, or a newer patched version --- IDENTIFIER: CWE-269 (Improper Privilege Management) The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C