The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized modification of site options due to a missing capability check on the fpd_update_options function in versions up to, and including, 4.6.9. This makes it possible for authenticated attackers with subscriber-level permissions to modify site options, including setting the default role to administrator which can allow privilege escalation.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2024-09-11T15:54:26.437Z

Reserved: 2023-04-05T18:21:59.693Z

Link: CVE-2021-4334

cve-icon Vulnrichment

Updated: 2024-08-03T17:23:10.547Z

cve-icon NVD

Status : Modified

Published: 2023-10-20T08:15:11.560

Modified: 2024-11-21T06:37:26.650

Link: CVE-2021-4334

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.