CVE-2021-4334: Fancy Product Designer <= 4.6.9 - Insufficient Authorization to Arbitrary Options Update via fpd_update_options
The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized modification of site options due to a missing capability check on the fpdupdateoptions function in versions up to, and including, 4.6.9. This makes it possible for authenticated attackers with subscriber-level permissions to modify site options, including setting the default role to administrator which can allow privilege escalation.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability description of CVE-2021-4334?
The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized modification of site options due to a missing capability check on the fpd_update_options function in versions up to, and including, 4.6.9.
What is the severity rating of CVE-2021-4334?
The severity rating of CVE-2021-4334 is high with a value of 8.8.
What software is affected by CVE-2021-4334?
The Fancy Product Designer plugin for WordPress versions up to, and including, 4.6.9.
How can an attacker exploit CVE-2021-4334?
Authenticated attackers with subscriber-level permissions can exploit CVE-2021-4334 to perform unauthorized modification of site options.
Are there any references available for CVE-2021-4334?
Yes, you can find references for CVE-2021-4334 at the following links: [Reference 1](https://support.fancyproductdesigner.com/support/discussions/topics/13000029981) and [Reference 2](https://www.wordfence.com/threat-intel/vulnerabilities/id/ea097cb7-85f4-4b6d-9f29-bc2636993f21?source=cve).