CyberRota Analysis
AI-GeneratedThe WC Fields Factory plugin for WordPress versions prior to 4.1.11 is vulnerable, allowing authenticated users with Subscriber-level access and above to manipulate post metadata, including WooCommerce product pricing. This could lead to unauthorized changes in product prices, potentially resulting in financial loss for businesses. WordPress site administrators, particularly those using WooCommerce, should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to its field-management AJAX action, allowing authenticated users with Subscriber-level access and above to create, modify and delete arbitrary post meta on any post, including WooCommerce products, regardless of ownership, and to manipulate stored pricing rules on a product to reduce its checkout price.