6.3

CVE-2021-4335

Fancy Product Designer <= 4.6.9 - Insufficient Authorization on Mulitple AJAX Actions

Fancy Product Designer <= 4.6.9 - Insufficient Authorization on Mulitple AJAX Actions

The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized access to data and modification of plugin settings due to a missing capability check on multiple AJAX functions in versions up to, and including, 4.6.9. This makes it possible for authenticated attackers with subscriber-level permissions to modify plugin settings, including retrieving arbitrary order information or creating/updating/deleting products, orders, or other sensitive information not associated with their own account.
Mögliche Gegenmaßnahme
Fancy Product Designer: Update to version 4.7.0, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
RadykalFancy Product Designer SwPlatformwordpress Version < 4.7.0
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Fancy Product Designer
Version *-4.6.9
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.4% 0.317
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.3 2.8 3.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
security@wordfence.com 6.3 2.8 3.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CWE-285 Improper Authorization

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

https://support.fancyproductdesigner.com/support/discussions/topics/13000029981
Release Notes
https://www.wordfence.com/threat-intel/vulnerabilities/id/644624d8-c193-4ee6-bc82-7ccda5d7f2ac?source=cve
Third Party Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/644624d8-c193-4ee6-bc82-7ccda5d7f2ac
Third Party Advisory