Data Modification Vulnerability in WooCommerce Filter Plus Plugin by WordPress
CVE-2025-13314
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 12 December 2025
What is CVE-2025-13314?
The Filter Plus plugin for WooCommerce has a security flaw that allows unauthorized users to modify plugin settings and create arbitrary filters. This is due to missing capability checks on critical AJAX actions, 'filter_save_settings' and 'add_filter_options', rendering the plugin vulnerable to attacks across all versions up to and including 1.1.5.
Affected Version(s)
Filter Plus β Product Filter & WordPress Filter 0 <= 1.1.6