Description
The Product Filtering by Categories, Tags, Price Range for WooCommerce – Filter Plus plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 1.1.5 due to a missing capability check on the 'filter_save_settings' and 'add_filter_options' AJAX actions. This makes it possible for unauthenticated attackers to modify the plugin's settings and create arbitrary filter options.
Problem types
Product status
* (semver)
Timeline
| 2025-12-11: | Disclosed |
Credits
Athiwat Tiprasaharn
References
www.wordfence.com/...-4e64-43f1-ba0a-56d10c8d1db9?source=cve
plugins.trac.wordpress.org/...core/admin/settings/action.php
plugins.trac.wordpress.org/...core/admin/settings/action.php
plugins.trac.wordpress.org/...core/admin/settings/action.php
plugins.trac.wordpress.org/...us/tags/1.1.5/base/enqueue.php
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.