Multiple XforWooCommerce Add-On Plugins (Various Versions) - Missing Authorization
Published Jun 7, 2023
8.8
HIGHCVSS 3.1
EPSS 1.27%
Description
Sixteen XforWooCommerce Add-On Plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the wp_ajax_svx_ajax_factory function in various versions listed below. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to read, edit, or delete WordPress settings, plugin settings, and to arbitrarily list all users on a WordPress website. The plugins impacted are: Product Filter for WooCommerce < 8.2.0, Improved Product Options for WooCommerce < 5.3.0, Improved Sale Badges for WooCommerce < 4.4.0, Share, Print and PDF Products for WooCommerce < 2.8.0, Product Loops for WooCommerce < 1.7.0, XforWooCommerce < 1.7.0, Package Quantity Discount < 1.2.0, Price Commander for WooCommerce < 1.3.0, Comment and Review Spam Control for WooCommerce < 1.5.0, Add Product Tabs for WooCommerce < 1.5.0, Autopilot SEO for WooCommerce < 1.6.0, Floating Cart < 1.3.0, Live Search for WooCommerce < 2.1.0, Bulk Add to Cart for WooCommerce < 1.3.0, Live Product Editor for WooCommerce < 4.7.0, and Warranties and Returns for WooCommerce < 5.3.0.
Affected products
-
- Version 0StatusaffectedConstraints<1.5.0
- Version
-
- Version 0StatusaffectedConstraints<1.6.0
- Version
-
- Version 0StatusaffectedConstraints<1.3.0
- Version
-
- Version 0StatusaffectedConstraints<1.5.0
- Version
-
- Version 0StatusaffectedConstraints<1.3.0
- Version
-
- Version 0StatusaffectedConstraints<5.3.0
- Version
-
- Version 0StatusaffectedConstraints<4.4.0
- Version
-
- Version 0StatusaffectedConstraints<4.7.0
- Version
-
- Version 0StatusaffectedConstraints<2.1.0
- Version
-
- Version 0StatusaffectedConstraints<1.2.0
- Version
-
- Version 0StatusaffectedConstraints<1.3.0
- Version
-
- Version 0StatusaffectedConstraints<8.2.0
- Version
-
- Version 0StatusaffectedConstraints<1.7.0
- Version
-
- Version 0StatusaffectedConstraints<2.8.0
- Version
-
- Version 0StatusaffectedConstraints<5.3.0
- Version
-
- Version 0StatusaffectedConstraints<1.7.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| XforWooCommerce | Add Product Tabs for WooCommerce | unaffected |
| ||||||
| XforWooCommerce | Autopilot SEO for WooCommerce | unaffected |
| ||||||
| XforWooCommerce | Bulk Add to Cart for WooCommerce | unaffected |
| ||||||
| XforWooCommerce | Comment and Review Spam Control for WooCommerce | unaffected |
| ||||||
| XforWooCommerce | Floating Cart for WooCommerce | unaffected |
| ||||||
| XforWooCommerce | Improved Product Options for WooCommerce | unaffected |
| ||||||
| XforWooCommerce | Improved Sale Badges for WooCommerce | unaffected |
| ||||||
| XforWooCommerce | Live Product Editor for WooCommerce | unaffected |
| ||||||
| XforWooCommerce | Live Search for WooCommerce | unaffected |
| ||||||
| XforWooCommerce | Package Quantity Discount | unaffected |
| ||||||
| XforWooCommerce | Price Commander for WooCommerce | unaffected |
| ||||||
| XforWooCommerce | Product Filter for WooCommerce | unaffected |
| ||||||
| XforWooCommerce | Product Loops for WooCommerce | unaffected |
| ||||||
| XforWooCommerce | Share, Print and PDF Products for WooCommerce | unaffected |
| ||||||
| XforWooCommerce | Warranties and Returns for WooCommerce | unaffected |
| ||||||
| XforWooCommerce | XforWooCommerce | unaffected |
|
- < 1.5.0
- < 1.6.0
- < 1.3.0
- < 1.5.0
- < 1.3.0
- < 5.3.0
- < 4.4.0
- < 4.7.0
- < 2.1.0
- < 1.2.0
- < 1.3.0
- < 8.2.0
- < 1.7.0
- < 2.8.0
- < 5.3.0
- < 1.7.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (4)
- https://blog.nintechnet.com/16-woocommerce-product-add-ons-plugins-fixed-vulnerabilities/ ExploitThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-34164 Advisory
- https://www.wordfence.com/threat-intel/vulnerabilities/id/05481984-7c18-4ec7-8d7c-831809c3e86b?source=cve Third Party Advisory
- https://xforwoocommerce.com/blog/change-log/xforwoocommerce-1-7-0/ Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://blog.nintechnet.com/16-woocommerce-product-add-ons-plugins-fixed-vulnerabilities/ | ExploitThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-34164 | Advisory | |
| https://www.wordfence.com/threat-intel/vulnerabilities/id/05481984-7c18-4ec7-8d7c-831809c3e86b?source=cve | Third Party Advisory | |
| https://xforwoocommerce.com/blog/change-log/xforwoocommerce-1-7-0/ | Vendor Advisory |
Change history (0)
No recorded changes yet.