What the vulnerability does
01Description
Missing Authorization vulnerability in Premmerce Premmerce Product Filter for WooCommerce premmerce-woocommerce-product-filter.This issue affects Premmerce Product Filter for WooCommerce: from n/a through <= 3.7.2.
Explanation of Vulnerability in Simple Terms
02Summary
The Premmerce Product Filter for WooCommerce plugin through version 3.7.2 lacks proper authorization checks on certain administrative functions. A logged-in user with low privileges can modify plugin settings or data without proper permission validation. This affects the integrity of filter configurations and site settings.
What an attacker can do
03Attacker Capabilities
Modify plugin settings or filter configurations without proper authorization.
Potential impact on your site
04Site Impact
Unauthorized users can alter product filter behavior, potentially disrupting customer experience or exposing unintended product data.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege user account (e.g., subscriber or customer) on the site.
Key dates
06Disclosure timeline
June 9, 2024
CVE published
April 28, 2026
Record updated