CVE-2021-4444: Product Filter by WooBeWoo <= 1.4.9 - Missing Authorization
The Product Filter by WooBeWoo plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 1.4.9 due to missing authorization checks on various functions. This makes it possible for unauthenticated attackers to perform unauthorized actions such as creating new filters and injecting malicious javascript into a vulnerable site. This was actively exploited at the time of discovery.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-4444?
CVE-2021-4444 has a medium severity rating due to its potential for unauthorized actions by unauthenticated attackers.
How do I fix CVE-2021-4444?
To fix CVE-2021-4444, upgrade the WooBeWoo Product Filter plugin to version 1.5.0 or later.
What type of vulnerability is CVE-2021-4444?
CVE-2021-4444 is an authorization bypass vulnerability affecting the WooBeWoo Product Filter plugin.
Who is affected by CVE-2021-4444?
Websites using the WooBeWoo Product Filter plugin versions up to and including 1.4.9 are affected by CVE-2021-4444.
What impact does CVE-2021-4444 have on my website?
CVE-2021-4444 allows attackers to perform unauthorized actions on your website, potentially compromising data integrity.