CVE Database
/

CVE-2021-4337

Back to search

CVE-2021-4337

Published: Jun 7, 2023

Modified: Apr 8, 2026

PUBLISHED

CVSS v3.1

8.8

HIGH

Description

Sixteen XforWooCommerce Add-On Plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the wp_ajax_svx_ajax_factory function in various versions listed below. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to read, edit, or delete WordPress settings, plugin settings, and to arbitrarily list all users on a WordPress website. The plugins impacted are: Product Filter for WooCommerce < 8.2.0, Improved Product Options for WooCommerce < 5.3.0, Improved Sale Badges for WooCommerce < 4.4.0, Share, Print and PDF Products for WooCommerce < 2.8.0, Product Loops for WooCommerce < 1.7.0, XforWooCommerce < 1.7.0, Package Quantity Discount < 1.2.0, Price Commander for WooCommerce < 1.3.0, Comment and Review Spam Control for WooCommerce < 1.5.0, Add Product Tabs for WooCommerce < 1.5.0, Autopilot SEO for WooCommerce < 1.6.0, Floating Cart < 1.3.0, Live Search for WooCommerce < 2.1.0, Bulk Add to Cart for WooCommerce < 1.3.0, Live Product Editor for WooCommerce < 4.7.0, and Warranties and Returns for WooCommerce < 5.3.0.

VendorProductVersions

XforWooCommerce

Package Quantity Discount

affected
0 - < 1.2.0

XforWooCommerce

Price Commander for WooCommerce

affected
0 - < 1.3.0

XforWooCommerce

Bulk Add to Cart for WooCommerce

affected
0 - < 1.3.0

XforWooCommerce

Floating Cart for WooCommerce

affected
0 - < 1.3.0

XforWooCommerce

Comment and Review Spam Control for WooCommerce

affected
0 - < 1.5.0

XforWooCommerce

Add Product Tabs for WooCommerce

affected
0 - < 1.5.0

XforWooCommerce

Autopilot SEO for WooCommerce

affected
0 - < 1.6.0

XforWooCommerce

XforWooCommerce

affected
0 - < 1.7.0

XforWooCommerce

Product Loops for WooCommerce

affected
0 - < 1.7.0

XforWooCommerce

Live Search for WooCommerce

affected
0 - < 2.1.0

XforWooCommerce

Share, Print and PDF Products for WooCommerce

affected
0 - < 2.8.0

XforWooCommerce

Improved Sale Badges for WooCommerce

affected
0 - < 4.4.0

XforWooCommerce

Live Product Editor for WooCommerce

affected
0 - < 4.7.0

XforWooCommerce

Warranties and Returns for WooCommerce

affected
0 - < 5.3.0

XforWooCommerce

Improved Product Options for WooCommerce

affected
0 - < 5.3.0

XforWooCommerce

Product Filter for WooCommerce

affected
0 - < 8.2.0

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now