KEVIntel
7.3
CVSS
High

CVE-2021-4444

PUBLISHED

Product Filter by WooBeWoo <= 1.4.9 - Missing Authorization

Exploited in the wild Remote Low complexity No user interaction
Vendor
woobewoo
Product
Product Filter by WBW
Published
Oct 16, 2024
EPSS

Description

The Product Filter by WooBeWoo plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 1.4.9 due to missing authorization checks on various functions. This makes it possible for unauthenticated attackers to perform unauthorized actions such as creating new filters and injecting malicious javascript into a vulnerable site. This was actively exploited at the time of discovery.

wordpress java

CVSS scores

CVSS v3.1 7.3 High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Exploitation status

Exploited in the wild

Recorded 2024-10-16 06:43:26 UTC · Source

SSVC decision points

Exploitation
none
Automatable
Yes
Technical impact
partial

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CVE Oct 16, 2024

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel