Impact
A missing authorization flaw in the BeRocket Advanced AJAX Product Filters plugin permits attackers to bypass intended access controls. The vulnerability is linked to incorrect configuration of security levels and carries a potential cross‑site request forgery component. When exploited, it could allow an attacker to perform privileged actions under the guise of a legitimate user, thereby compromising confidentiality and integrity of the site’s product filtering functionality.
Affected Systems
The issue affects the BeRocket Advanced AJAX Product Filters plugin for WordPress, specifically all versions through 1.6.3.3. Versions 1.6.3.4 and later include the fix.
Risk and Exploitability
The CVSS score of 5.4 classifies the vulnerability as medium severity. EPSS information is not available, so the likelihood of exploitation cannot be quantified, but the plugin’s web‑based nature suggests that a remote attacker could trigger the flaw through crafted requests. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to target a WordPress site running the affected plugin and could potentially execute unauthorized actions via CSRF or direct requests, assuming insufficient access control checks.
OpenCVE Enrichment