CVE-2026-3138Disclosure

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Product Filter for WooCommerce by WBW plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check in all versions up to, and including, 3.1.2. This is due to the plugin's MVC framework dynamically registering unauthenticated AJAX handlers via `wp_ajax_nopriv_` hooks without verifying user capabilities, combined with the base controller's `__call()` magic method forwarding undefined method calls to the model layer, and the `havePermissions()` method defaulting to `true` when no permissions are explicitly defined. This makes it possible for unauthenticated attackers to truncate the plugin's `wp_wpf_filters` database table via a crafted AJAX request with `action=delete`, permanently destroying all filter configurations.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-24); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-24: 1Mentions · 2026-04-15: 1Patch / Workaround · 2026-04-15: 1Technical Details · 2026-03-24: 103-2404-15
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-241
Disclosure1
2026-04-151
Patch1
Full discourse2 posts
  • Security Arsenal, LLC@SecurityAr58409
    Patch

    🔒 #CyberSecurity How to Protect Against Gainsight Assist Vulnerabilities: Patching CVE-2026-3138… "Security teams must remain vigilant regarding the software extensions integrated…" 🔗 https://securityarsenal.com/blog/how-to-protect-against-gainsight-assist-vulnerabilities-patching-cve-2026-31381-and-cve-2026-31382 #CyberSecurity #ThreatIntel #alertfatigue #triage #alertmonitor

    Post summary

    The blog post warns about Gainsight Assist vulnerabilities and advises applying patches for CVE-2026-31381 and CVE-2026-31382 to protect systems.

    0000024
    10 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3138 The Product Filter for WooCommerce by WBW plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check in all versions up to, and incl… https://www.cve.org/CVERecord?id=CVE-2026-3138

    Post summary

    The CVE identifies a missing capability check in the Product Filter for WooCommerce plugin, leading to potential data loss; no PoC, exploit or patch information is provided.

    0000083
    56.8K followersView on X

Explore more