CVE-2021-4337
07.06.2023, 13:15
Sixteen XforWooCommerce Add-On Plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the wp_ajax_svx_ajax_factory function in various versions listed below. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to read, edit, or delete WordPress settings, plugin settings, and to arbitrarily list all users on a WordPress website. The plugins impacted are: Product Filter for WooCommerce < 8.2.0, Improved Product Options for WooCommerce < 5.3.0, Improved Sale Badges for WooCommerce < 4.4.0, Share, Print and PDF Products for WooCommerce < 2.8.0, Product Loops for WooCommerce < 1.7.0, XforWooCommerce < 1.7.0, Package Quantity Discount < 1.2.0, Price Commander for WooCommerce < 1.3.0, Comment and Review Spam Control for WooCommerce < 1.5.0, Add Product Tabs for WooCommerce < 1.5.0, Autopilot SEO for WooCommerce < 1.6.0, Floating Cart < 1.3.0, Live Search for WooCommerce < 2.1.0, Bulk Add to Cart for WooCommerce < 1.3.0, Live Product Editor for WooCommerce < 4.7.0, and Warranties and Returns for WooCommerce < 5.3.0.Enginsight
Vendor | Product | Version |
---|---|---|
xforwoocommerce | add_product_tabs | 𝑥 < 1.5.0 |
xforwoocommerce | autopilot_seo | 𝑥 < 1.6.0 |
xforwoocommerce | bulk_add_to_cart | 𝑥 < 1.3.0 |
xforwoocommerce | comment_and_review_spam_control | 𝑥 < 1.5.0 |
xforwoocommerce | floating_cart | 𝑥 < 1.3.0 |
xforwoocommerce | improved_product_options | 𝑥 < 5.3.0 |
xforwoocommerce | improved_sale_badges | 𝑥 < 4.4.0 |
xforwoocommerce | live_product_editor | 𝑥 < 4.7.0 |
xforwoocommerce | live_search | 𝑥 < 2.1.0 |
xforwoocommerce | package_quantity | 𝑥 < 1.2.0 |
xforwoocommerce | price_commander | 𝑥 < 1.3.0 |
xforwoocommerce | product_filter | 𝑥 < 8.2.0 |
xforwoocommerce | product_loops | 𝑥 < 1.7.0 |
xforwoocommerce | share\,_print_and_pdf_products | 𝑥 < 2.8.0 |
xforwoocommerce | warranties_and_returns | 𝑥 < 5.3.0 |
xforwoocommerce | xforwoocommerce | 𝑥 < 1.7.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References