he HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.6.1 via the woof_messenger_remove_subscr AJAX action due to missing validation on the 'key' user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to unsubscribe users from a product notification sign-ups, if they can successfully obtain or brute force the key value for users who signed up to receive notifications. This vulnerability requires the plugin's Products Messenger extension to be enabled.
Configuration 1 (hide)
|
12 Mar 2025, 18:05
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:pluginus:husky_-_products_filter_professional_for_woocommerce:*:*:*:*:*:wordpress:*:* | |
| First Time |
Pluginus
Pluginus husky - Products Filter Professional For Woocommerce |
|
| References | () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3156511%40woocommerce-products-filter&old=3129454%40woocommerce-products-filter&sfp_email=&sfph_mail= - Patch | |
| References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/daf6b0d5-79a6-4b8f-924e-9e78cb2b5742?source=cve - Third Party Advisory |
26 Sep 2024, 13:32
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
25 Sep 2024, 03:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Published : 2024-09-25 03:15
Updated : 2025-03-12 18:05
NVD link : CVE-2024-7491
Mitre link : CVE-2024-7491
CVE.ORG link : CVE-2024-7491
JSON object : View
Missing Authorization