CVE-2021-4335: Fancy Product Designer <= 4.6.9 - Insufficient Authorization on Mulitple AJAX Actions
The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized access to data and modification of plugin settings due to a missing capability check on multiple AJAX functions in versions up to, and including, 4.6.9. This makes it possible for authenticated attackers with subscriber-level permissions to modify plugin settings, including retrieving arbitrary order information or creating/updating/deleting products, orders, or other sensitive information not associated with their own account.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-4335?
CVE-2021-4335 is a vulnerability in the Fancy Product Designer plugin for WordPress that allows unauthorized access to data and modification of plugin settings.
What is the severity of CVE-2021-4335?
The severity of CVE-2021-4335 is medium, with a severity value of 6.3.
How does CVE-2021-4335 affect the Fancy Product Designer plugin?
CVE-2021-4335 affects versions up to, and including, 4.6.9 of the Fancy Product Designer plugin for WordPress.
How can an attacker exploit CVE-2021-4335?
An authenticated attacker with subscriber-level access can exploit CVE-2021-4335 to gain unauthorized access to data and modify plugin settings.
Are there any references available for CVE-2021-4335?
Yes, you can find more information about CVE-2021-4335 at the following references: [link1](https://support.fancyproductdesigner.com/support/discussions/topics/13000029981), [link2](https://www.wordfence.com/threat-intel/vulnerabilities/id/644624d8-c193-4ee6-bc82-7ccda5d7f2ac?source=cve)