CVE-2021-4444

Product Filter by WooBeWoo <= 1.4.9 - Missing Authorization

Basic Information

CVE State
PUBLISHED
Reserved Date
October 15, 2024
Published Date
October 16, 2024
Last Updated
October 16, 2024
Vendor
woobewoo
Product
Product Filter by WBW
Description
The Product Filter by WooBeWoo plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 1.4.9 due to missing authorization checks on various functions. This makes it possible for unauthenticated attackers to perform unauthorized actions such as creating new filters and injecting malicious javascript into a vulnerable site. This was actively exploited at the time of discovery.
Tags
wordpress

CVSS Scores

CVSS v3.1

7.3 - HIGH

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

SSVC Information

Exploitation
none
Automatable
Yes
Technical Impact
partial

Exploit Status

Exploited in the Wild
Yes (2024-10-16 06:43:26 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CVE 2024-10-16 06:43:26 UTC

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel