Impact
The Product Filter by WBW plugin for WordPress lacks a capability check on the 'approveNotice' action in all versions up to 3.0.0, allowing any unauthenticated user to modify the plugin's settings. This missing authorization check can permit attackers to change configuration options, potentially disabling protective features or enabling malicious behaviors. The primary impact is unauthorized modification of plugin settings that could compromise site functionality and security.
Affected Systems
The affected product is Product Filter for WooCommerce by WBW, commonly known as the Product Filter by WBW plugin. All releases through version 3.0.0 are affected; newer releases (3.0.1 and beyond) are not documented as vulnerable. Any WordPress site deploying the plugin at or below this version should review its installation.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity, and the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, implying no known widespread exploitation. Attackers can exploit the flaw by accessing the plugin's admin settings page without authentication, sending a request to the 'approveNotice' endpoint. Because the vulnerability applies to unauthenticated users, no prior permissions are needed, making it a relatively low-bar threat, but still significant due to the potential for broad configuration changes.
OpenCVE Enrichment