CVE · Medium

CVE-2023-40334 — HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.4.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-40334 HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.4.3 Missing Authorization Medium 4.3 < 1.3.4.3 1.3.4.3 2023-11-23

CVE-2023-40334

The HUSKY – Products Filter for WooCommerce plugin (previously known as WOOF) versions before 1.3.4.3 contain a broken access control vulnerability that allows unauthenticated users to perform privileged actions due to missing authorization and nonce checks. An attacker could exploit this flaw to execute functions that should be restricted to higher-privileged users. The vulnerability was discovered by thiennv and has been remediated in version 1.3.4.3 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.