Product Filtering by Categories, Tags, Price Range for WooCommerce Missing Authorization Vulnerability

Vulnerability

A vulnerability exists in the Product Filtering by Categories, Tags, Price Range for WooCommerce - Filter Plus plugin for WordPress, in all versions through 1.1.5. The issue arises from a lack of proper capability checks on the 'filter_save_settings' and 'add_filter_options' AJAX actions. This flaw allows unauthenticated attackers to unauthorizedly modify the plugin's settings and create custom filter options.

Impact

Exploitation of this vulnerability could lead to unauthorized changes in the plugin's settings and the creation of arbitrary filter options, potentially disrupting the site's functionality or user experience.

Reproduction

To reproduce this vulnerability, send an AJAX request to the 'wp_ajax_add_filter_options' or 'wp_ajax_filter_save_settings' actions without the necessary authorization. The request can include parameters to modify the plugin's settings or add new filter options. Since the vulnerability allows unauthenticated access, no login or user credentials are required.

Added: Dec 12, 2025, 5:35 AM
Updated: Dec 12, 2025, 5:35 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
8.4
remediation
0.0
relevance
1.3
threat
4.8
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.