Product Filter by WBW WordPress Plugin Missing Authorization Vulnerability in Versions Through 3.0.0
Vulnerability
A vulnerability exists in the Product Filter by WBW plugin for WordPress, all versions through 3.0.0, allowing unauthorized data modification. The issue arises from a missing capability check on the 'approveNotice' action, enabling unauthenticated attackers to alter the plugin's settings.
Impact
Exploitation of this vulnerability allows for unauthorized changes to the plugin's settings, which could disrupt the functionality of the product filtering system on the WordPress site.
Remediation
Users can update to version 3.0.1 or a newer patched version to address this vulnerability.
Added: Oct 25, 2025, 6:29 AM
Updated: Oct 25, 2025, 6:29 AM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
0.6exploitability
8.1remediation
7.7relevance
0.8threat
3.2urgency
2.9incentive
5.8Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
