Executive brief
BeRocket Advanced AJAX Product Filters is a WordPress plugin used to add advanced search and filtering capabilities to e-commerce websites. A security flaw in the plugin's access control settings allows logged-in users with low-level permissions to perform actions they should not be authorized to do. This could lead to unauthorized changes to product filter settings or the exposure of internal configuration data.
Technical details
A missing authorization vulnerability (CWE-862) exists in the BeRocket Advanced AJAX Product Filters plugin for WordPress. The flaw stems from incorrectly configured access control security levels, which fail to properly validate user permissions before executing certain functions. An authenticated attacker with subscriber-level privileges can exploit this over the network to perform unauthorized actions or access restricted settings. The vulnerability is addressed in version 1.6.3.4.
Affected products
- BeRocket Advanced AJAX Product Filters n/a through 1.6.3.3
Timeline
- 2022-12-01: disclosed: Reported by István Márton
- 2023-07-12: patched: Patch released in version 1.6.3.4
- 2026-06-11: advisory: NVD publication date