CVE · High

CVE-2024-43121 — HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.6.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-43121 HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.6.2 Improper Privilege Management High 7.2 < 1.3.6.2 1.3.6.2 2024-08-07

CVE-2024-43121

The HUSKY – Products Filter Professional for WooCommerce plugin through version 1.3.6.1 contains a vulnerability in the do_import_data() function that fails to properly validate options before processing them. Authenticated users with Shop Manager privileges or higher can exploit this flaw to modify arbitrary WordPress options, including changing the default registration role to administrator and enabling user registration. By leveraging these modified settings, attackers can create new accounts with administrative capabilities, effectively gaining full control over the affected WordPress installation.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.