A remote code execution issue was discovered in the WooCommerce Products Filter (aka WOOF) plugin before 2.2.0 for WordPress, as demonstrated by the shortcode parameter in a woof_redraw_woof action. The plugin implemented a page redraw AJAX function accessible to anyone without any authentication. WordPress shortcode markup in the "shortcode" parameters would be evaluated. Normally unauthenticated users can't evaluate shortcodes as they are often sensitive.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2018-03-14 12:29
Updated : 2019-10-02 17:03
NVD link : CVE-2018-8710
Mitre link : CVE-2018-8710
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
woocommerce-filter
- woocommerce_products_filter