plugin

Woocommerce Ajax Filters Vulnerabilities

11 known security issues reported for the Woocommerce Ajax Filters WordPress plugin. Most recent disclosed Aug 4, 2026.

3 high 2 medium

Running Woocommerce Ajax Filters on your site? Check whether your installed version is affected.

Scan your site free

Advanced AJAX Product Filters <= 3.2.0.3 - Unauthenticated Stored Cross-Site Scripting

high

The Advanced AJAX Product Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenev...

CVSS:
7.2
Affected:
up to 3.2.0.3
Fixed in:
3.2.1
Disclosed:
Aug 4, 2026

CVE-2026-66439 on NVD →

Advanced AJAX Product Filters <= 3.1.9.6 - Authenticated (Author+) PHP Object Injection via Live Composer Compatibility

high

The Advanced AJAX Product Filters plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.9.6 via deserialization of untrusted input in the shortcode_check function within the Live Composer compatibility layer. This makes it possible for authenticated attackers, with Author-...

CVSS:
8.8
Affected:
up to 3.1.9.6
Fixed in:
3.1.9.7
Disclosed:
Feb 17, 2026

CVE-2026-1426 on NVD →

Advanced AJAX Product Filters <= 1.6.8.1 - Reflected Cross-Site Scripting

medium

The Advanced AJAX Product Filters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nonce' parameter in all versions up to, and including, 1.6.8.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...

CVSS:
6.1
Affected:
up to 1.6.8.1
Fixed in:
1.6.8.2
Disclosed:
Feb 27, 2025

CVE-2025-1505 on NVD →

Advanced AJAX Product Filters [woocommerce-ajax-filters] < 1.5.4.7

unknown

[en] The Advanced AJAX Product Filters WordPress plugin does not sanitise the 'term_id' POST parameter before outputting it in the page, leading to reflected Cross-Site Scripting issue.

Affected:
up to 1.5.4.7
Fixed in:
1.5.4.7
Disclosed:
Jan 16, 2024

CVE-2021-24432 on NVD →

Advanced AJAX Product Filters <= 1.5.4.6 - Reflected Cross-Site Scripting

medium

The Advanced AJAX Product Filters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘term_id’ parameter in versions up to, and including, 1.5.4.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...

CVSS:
6.1
Affected:
up to 1.5.4.6
Fixed in:
1.5.4.7
Disclosed:
Jun 9, 2021

CVE-2021-24432 on NVD →

Advanced AJAX Product Filters [woocommerce-ajax-filters] < 1.3.7

unknown

Unauthenticated Plugin Settings Update vulnerability found in WordPress Advanced AJAX Product Filters plugin (versions <= 1.3.6.1).

Affected:
up to 1.3.7
Fixed in:
1.3.7
Disclosed:
Sep 19, 2019

WooCommerce AJAX Product Filters <= 1.3.6 - Arbitrary Settings Update

high

The WooCommerce AJAX Product Filters plugin for WordPress is vulnerable to Arbitrary Settings Update in versions up to, and including, 1.3.6. This is due to incorrect usage of the admin_init hook. This makes it possible for unauthenticated attackers to change any of the plugin settings and redirect users to malicious U...

CVSS:
8.3
Affected:
up to 1.3.7
Fixed in:
1.3.7
Disclosed:
Sep 18, 2019

Advanced AJAX Product Filters [woocommerce-ajax-filters] < 1.3.7

unknown

The WooCommerce AJAX Product Filters plugin for WordPress is vulnerable to Arbitrary Settings Update in versions up to, and including, 1.3.6. This is due to incorrect usage of the admin_init hook. This makes it possible for unauthenticated attackers to change any of the plugin settings and redirect users to malicious U...

Affected:
up to 1.3.7
Fixed in:
1.3.7
Disclosed:
Sep 18, 2019

Advanced AJAX Product Filters [woocommerce-ajax-filters] < 1.6.3.4

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 1.6.3.4
Fixed in:
1.6.3.4

CVE-2022-45813 on NVD →

Advanced AJAX Product Filters [woocommerce-ajax-filters] < 1.3.7

unknown

The Advanced AJAX Product Filters WordPress plugin was affected by an Unauthenticated Plugin Settings Update security vulnerability.

Affected:
up to 1.3.7
Fixed in:
1.3.7

Advanced AJAX Product Filters [woocommerce-ajax-filters] < 1.6.8.2

unknown
Affected:
up to 1.6.8.2
Fixed in:
1.6.8.2

CVE-2025-1505 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database