๐Ÿ” CVE Alert

CVE-2021-4337

HIGH 8.8

Multiple XforWooCommerce Add-On Plugins (Various Versions) - Missing Authorization

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

Sixteen XforWooCommerce Add-On Plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the wp_ajax_svx_ajax_factory function in various versions listed below. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to read, edit, or delete WordPress settings, plugin settings, and to arbitrarily list all users on a WordPress website. The plugins impacted are: Product Filter for WooCommerce < 8.2.0, Improved Product Options for WooCommerce < 5.3.0, Improved Sale Badges for WooCommerce < 4.4.0, Share, Print and PDF Products for WooCommerce < 2.8.0, Product Loops for WooCommerce < 1.7.0, XforWooCommerce < 1.7.0, Package Quantity Discount < 1.2.0, Price Commander for WooCommerce < 1.3.0, Comment and Review Spam Control for WooCommerce < 1.5.0, Add Product Tabs for WooCommerce < 1.5.0, Autopilot SEO for WooCommerce < 1.6.0, Floating Cart < 1.3.0, Live Search for WooCommerce < 2.1.0, Bulk Add to Cart for WooCommerce < 1.3.0, Live Product Editor for WooCommerce < 4.7.0, and Warranties and Returns for WooCommerce < 5.3.0.

CWE CWE-862
Vendor xforwoocommerce
Product package quantity discount
Published Jun 7, 2023
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for xforwoocommerce package quantity discount

Be the first to know when new high vulnerabilities affecting xforwoocommerce package quantity discount are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

XforWooCommerce / Package Quantity Discount
0 < 1.2.0
XforWooCommerce / Price Commander for WooCommerce
0 < 1.3.0
XforWooCommerce / Bulk Add to Cart for WooCommerce
0 < 1.3.0
XforWooCommerce / Floating Cart for WooCommerce
0 < 1.3.0
XforWooCommerce / Comment and Review Spam Control for WooCommerce
0 < 1.5.0
XforWooCommerce / Add Product Tabs for WooCommerce
0 < 1.5.0
XforWooCommerce / Autopilot SEO for WooCommerce
0 < 1.6.0
XforWooCommerce / XforWooCommerce
0 < 1.7.0
XforWooCommerce / Product Loops for WooCommerce
0 < 1.7.0
XforWooCommerce / Live Search for WooCommerce
0 < 2.1.0
XforWooCommerce / Share, Print and PDF Products for WooCommerce
0 < 2.8.0
XforWooCommerce / Improved Sale Badges for WooCommerce
0 < 4.4.0
XforWooCommerce / Live Product Editor for WooCommerce
0 < 4.7.0
XforWooCommerce / Warranties and Returns for WooCommerce
0 < 5.3.0
XforWooCommerce / Improved Product Options for WooCommerce
0 < 5.3.0
XforWooCommerce / Product Filter for WooCommerce
0 < 8.2.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/05481984-7c18-4ec7-8d7c-831809c3e86b?source=cve blog.nintechnet.com: https://blog.nintechnet.com/16-woocommerce-product-add-ons-plugins-fixed-vulnerabilities/ xforwoocommerce.com: https://xforwoocommerce.com/blog/change-log/xforwoocommerce-1-7-0/

Credits

Jerome Bruandet