PT-2026-27327 · Woobewoo · Product Filter For Woocommerce By Wbw

Youssef Elouaer

·

Published

2026-03-24

·

Updated

2026-03-24

·

CVE-2026-3138

CVSS v3.1

6.5

Medium

AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
The Product Filter for WooCommerce by WBW plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check in all versions up to, and including, 3.1.2. This is due to the plugin's MVC framework dynamically registering unauthenticated AJAX handlers via wp ajax nopriv hooks without verifying user capabilities, combined with the base controller's call() magic method forwarding undefined method calls to the model layer, and the havePermissions() method defaulting to true when no permissions are explicitly defined. This makes it possible for unauthenticated attackers to truncate the plugin's wp wpf filters database table via a crafted AJAX request with action=delete, permanently destroying all filter configurations.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-3138

Affected Products

Product Filter For Woocommerce By Wbw