PT-2026-27327 · Woobewoo · Product Filter For Woocommerce By Wbw

Youssef Elouaer

·

Published

2026-03-24

·

Updated

2026-04-15

·

CVE-2026-3138

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Product Filter for WooCommerce by WBW versions prior to 3.1.3
Description A missing capability check allows unauthenticated attackers to cause unauthorized data loss. The plugin MVC framework dynamically registers unauthenticated AJAX handlers via wp ajax nopriv hooks without verifying user capabilities. This is combined with the base controller call() magic method forwarding undefined method calls to the model layer, while the havePermissions() method defaults to true when no permissions are explicitly defined. An attacker can truncate the wp wpf filters database table by sending a crafted AJAX request to the endpoint using the action variable set to 'delete', resulting in the permanent destruction of all filter configurations.
Recommendations Update to a version later than 3.1.2.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-3138

Affected Products

Product Filter For Woocommerce By Wbw