CVE-2024-43121
The HUSKY – Products Filter Professional for WooCommerce plugin through version 1.3.6.1 contains a vulnerability in the do_import_data() function that fails to properly validate options before processing them. Authenticated users with Shop Manager privileges or higher can exploit this flaw to modify arbitrary WordPress options, including changing the default registration role to administrator and enabling user registration. By leveraging these modified settings, attackers can create new accounts with administrative capabilities, effectively gaining full control over the affected WordPress installation.
Based on public CVE data (MITRE/NVD).