Product Filter for WooCommerce [prdctfltr] <= 9.1.2 (unfixed)
unknown
[en] Incorrect Privilege Assignment vulnerability in XforWooCommerce Product Filter for WooCommerce prdctfltr allows Privilege Escalation.This issue affects Product Filter for WooCommerce: from n/a through <= 9.1.2.
- Affected:
- up to 9.1.2
- Fix:
- No patched version reported
- Disclosed:
- Feb 20, 2026
CVE-2025-69378 on NVD →
Product Filter for WooCommerce <= 9.1.2 - Authenticated (Shop Manager+) Privilege Escalation
high
The Product Filter for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 9.1.2. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to elevate their privileges to that of an administrator.
- CVSS:
- 7.2
- Affected:
- up to 9.1.2
- Fixed in:
- 9.1.3
- Disclosed:
- Feb 5, 2026
CVE-2025-69378 on NVD →
Product Filter for WooCommerce [prdctfltr] < 8.2.0
unknown
[en] Sixteen XforWooCommerce Add-On Plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the wp_ajax_svx_ajax_factory function in various versions listed below. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to read, edit, or...
- Affected:
- up to 8.2.0
- Fixed in:
- 8.2.0
- Disclosed:
- Jun 7, 2023
CVE-2021-4337 on NVD →
Product Filter for WooCommerce [prdctfltr] < 8.2.0
unknown
Multiple vulnerabilities (Authenticated Arbitrary WordPress Options Change, Read and Deletion / Authenticated User Enumeration / Authenticated Plugin Settings Change, Import and Export) were discovered by Jerome Bruandet (NinTechNet) in WordPress Product Filter for WooCommerce plugin (versions <= 8.1.1).
- Affected:
- up to 8.2.0
- Fixed in:
- 8.2.0
- Disclosed:
- Sep 20, 2021
Multiple XforWooCommerce Add-On Plugins (Various Versions) - Missing Authorization
high
Sixteen XforWooCommerce Add-On Plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the wp_ajax_svx_ajax_factory function in various versions listed below. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to read, edit, or dele...
- CVSS:
- 8.8
- Affected:
- up to 8.2.0
- Fixed in:
- 8.2.0
- Disclosed:
- Sep 7, 2021
CVE-2021-4337 on NVD →
Product Filter for WooCommerce [prdctfltr] < 8.2.0
unknown
The svx_ajax_factory AJAX action of the plugins, available to authenticated users, do not have CSRF and capability checks, which could allow any authenticated user, such as subscriber to change/view/delete arbitrary WordPress options, retrieve the list of users, import/export/update the plugins' settings.
- Affected:
- up to 8.2.0
- Fixed in:
- 8.2.0
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database