Medium severity5.3OSV Advisory· Published Oct 25, 2025· Updated Apr 15, 2026
CVE-2025-11269
CVE-2025-11269
Description
The Product Filter by WBW plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'approveNotice' action in all versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers to update the plugin's settings.
Affected products
1- Range: v2.8.4, v2.8.5, v2.8.6, …
Patches
1313f69908cadVulnerability mechanics
Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
3News mentions
0No linked articles in our index yet.