Advanced AJAX Product Filters <= 3.2.0.3 - Unauthenticated Stored Cross-Site Scripting
high
The Advanced AJAX Product Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenev...
- CVSS:
- 7.2
- Affected:
- up to 3.2.0.3
- Fixed in:
- 3.2.1
- Disclosed:
- Aug 4, 2026
CVE-2026-66439 on NVD →
Advanced AJAX Product Filters <= 3.1.9.6 - Authenticated (Author+) PHP Object Injection via Live Composer Compatibility
high
The Advanced AJAX Product Filters plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.9.6 via deserialization of untrusted input in the shortcode_check function within the Live Composer compatibility layer. This makes it possible for authenticated attackers, with Author-...
- CVSS:
- 8.8
- Affected:
- up to 3.1.9.6
- Fixed in:
- 3.1.9.7
- Disclosed:
- Feb 17, 2026
CVE-2026-1426 on NVD →
Advanced AJAX Product Filters <= 1.6.8.1 - Reflected Cross-Site Scripting
medium
The Advanced AJAX Product Filters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nonce' parameter in all versions up to, and including, 1.6.8.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...
- CVSS:
- 6.1
- Affected:
- up to 1.6.8.1
- Fixed in:
- 1.6.8.2
- Disclosed:
- Feb 27, 2025
CVE-2025-1505 on NVD →
Advanced AJAX Product Filters [woocommerce-ajax-filters] < 1.5.4.7
unknown
[en] The Advanced AJAX Product Filters WordPress plugin does not sanitise the 'term_id' POST parameter before outputting it in the page, leading to reflected Cross-Site Scripting issue.
- Affected:
- up to 1.5.4.7
- Fixed in:
- 1.5.4.7
- Disclosed:
- Jan 16, 2024
CVE-2021-24432 on NVD →
Advanced AJAX Product Filters <= 1.5.4.6 - Reflected Cross-Site Scripting
medium
The Advanced AJAX Product Filters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘term_id’ parameter in versions up to, and including, 1.5.4.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...
- CVSS:
- 6.1
- Affected:
- up to 1.5.4.6
- Fixed in:
- 1.5.4.7
- Disclosed:
- Jun 9, 2021
CVE-2021-24432 on NVD →
Advanced AJAX Product Filters [woocommerce-ajax-filters] < 1.3.7
unknown
Unauthenticated Plugin Settings Update vulnerability found in WordPress Advanced AJAX Product Filters plugin (versions <= 1.3.6.1).
- Affected:
- up to 1.3.7
- Fixed in:
- 1.3.7
- Disclosed:
- Sep 19, 2019
WooCommerce AJAX Product Filters <= 1.3.6 - Arbitrary Settings Update
high
The WooCommerce AJAX Product Filters plugin for WordPress is vulnerable to Arbitrary Settings Update in versions up to, and including, 1.3.6. This is due to incorrect usage of the admin_init hook. This makes it possible for unauthenticated attackers to change any of the plugin settings and redirect users to malicious U...
- CVSS:
- 8.3
- Affected:
- up to 1.3.7
- Fixed in:
- 1.3.7
- Disclosed:
- Sep 18, 2019
Advanced AJAX Product Filters [woocommerce-ajax-filters] < 1.3.7
unknown
The WooCommerce AJAX Product Filters plugin for WordPress is vulnerable to Arbitrary Settings Update in versions up to, and including, 1.3.6. This is due to incorrect usage of the admin_init hook. This makes it possible for unauthenticated attackers to change any of the plugin settings and redirect users to malicious U...
- Affected:
- up to 1.3.7
- Fixed in:
- 1.3.7
- Disclosed:
- Sep 18, 2019
Advanced AJAX Product Filters [woocommerce-ajax-filters] < 1.6.3.4
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 1.6.3.4
- Fixed in:
- 1.6.3.4
CVE-2022-45813 on NVD →
Advanced AJAX Product Filters [woocommerce-ajax-filters] < 1.3.7
unknown
The Advanced AJAX Product Filters WordPress plugin was affected by an Unauthenticated Plugin Settings Update security vulnerability.
- Affected:
- up to 1.3.7
- Fixed in:
- 1.3.7
Advanced AJAX Product Filters [woocommerce-ajax-filters] < 1.6.8.2
unknown
- Affected:
- up to 1.6.8.2
- Fixed in:
- 1.6.8.2
CVE-2025-1505 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database