plugin

Woocommerce Products Filter Vulnerabilities

49 known security issues reported for the Woocommerce Products Filter WordPress plugin. Most recent disclosed Jul 17, 2026.

6 critical 7 high 11 medium

Running Woocommerce Products Filter on your site? Check whether your installed version is affected.

Scan your site free

HUSKY - Products Filter Professional for WooCommerce <= 1.4.0 - Authenticated (Shop manager+) Local File Inclusion

medium

The HUSKY - Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.0. This makes it possible for authenticated attackers, with shop manager-level access and above, to include and execute arbitrary files on the server, allowing the ex...

CVSS:
6.6
Affected:
up to 1.4.0
Fixed in:
1.4.1
Disclosed:
Jul 17, 2026

CVE-2026-15244 on NVD →

HUSKY &#8211; Products Filter Professional for WooCommerce [woocommerce-products-filter] < 1.3.7.4

unknown

[en] The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.7.3 via the "woof_add_subscr" function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, wi...

Affected:
up to 1.3.7.4
Fixed in:
1.3.7.4
Disclosed:
Dec 18, 2025

CVE-2025-13110 on NVD →

HUSKY – Products Filter Professional for WooCommerce <= 1.3.7.3 - Authenticated (Subscriber+) Insecure Direct Object Reference via 'woof_add_subscr'

medium

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.7.3 via the "woof_add_subscr" function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with su...

CVSS:
4.3
Affected:
up to 1.3.7.3
Fixed in:
1.3.7.4
Disclosed:
Dec 17, 2025

CVE-2025-13110 on NVD →

HUSKY – Products Filter Professional for WooCommerce <= 1.3.7.2 - Authenticated (Subscriber+) Insecure Direct Object Reference via 'woof_add_query/woof_remove_query'

medium

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.7.2 via the "woof_add_query" and "woof_remove_query" functions due to missing validation on a user controlled key. This makes it possible for authenti...

CVSS:
4.3
Affected:
up to 1.3.7.2
Fixed in:
1.3.7.3
Disclosed:
Dec 3, 2025

CVE-2025-13109 on NVD →

HUSKY &#8211; Products Filter Professional for WooCommerce [woocommerce-products-filter] < 1.3.7.3 (closed)

unknown

[en] The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.7.2 via the "woof_add_query" and "woof_remove_query" functions due to missing validation on a user controlled key. This makes it possible for aut...

Affected:
up to 1.3.7.3
Fixed in:
1.3.7.3
Disclosed:
Dec 3, 2025

CVE-2025-13109 on NVD →

HUSKY &#8211; Products Filter Professional for WooCommerce [woocommerce-products-filter] < 1.3.7.2 (closed)

unknown

[en] The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to blind SQL Injection via the `phrase` parameter in all versions up to, and including, 1.3.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This...

Affected:
up to 1.3.7.2
Fixed in:
1.3.7.2
Disclosed:
Oct 28, 2025

CVE-2025-11735 on NVD →

HUSKY – Products Filter Professional for WooCommerce <= 1.3.7.1 - Unauthenticated SQL Injection via `phrase` Parameter

high

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to blind SQL Injection via the `phrase` parameter in all versions up to, and including, 1.3.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This make...

CVSS:
7.5
Affected:
up to 1.3.7.1
Fixed in:
1.3.7.2
Disclosed:
Oct 27, 2025

CVE-2025-11735 on NVD →

HUSKY &#8211; Products Filter Professional for WooCommerce [woocommerce-products-filter] < 1.3.7.1 (closed)

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RealMag777 HUSKY allows PHP Local File Inclusion. This issue affects HUSKY: from n/a through 1.3.7.

Affected:
up to 1.3.7.1
Fixed in:
1.3.7.1
Disclosed:
Jun 20, 2025

CVE-2025-52708 on NVD →

HUSKY <= 1.3.7 - Authenticated (Contributor+) Local File Inclusion

high

The HUSKY plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.7. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can...

CVSS:
8.8
Affected:
up to 1.3.7
Fixed in:
1.3.7.1
Disclosed:
Jun 19, 2025

CVE-2025-52708 on NVD →

HUSKY &#8211; Products Filter Professional for WooCommerce [woocommerce-products-filter] < 1.3.6.5 (closed)

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PluginUs.Net HUSKY allows PHP Local File Inclusion.This issue affects HUSKY: from n/a through 1.3.6.4.

Affected:
up to 1.3.6.5
Fixed in:
1.3.6.5
Disclosed:
Mar 27, 2025

CVE-2025-26890 on NVD →

HUSKY – Products Filter Professional for WooCommerce <= 1.3.6.4 - Unauthenticated Local File Inclusion

high

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.6.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to include and execute arbitrary files on the server, allowing th...

CVSS:
7.5
Affected:
up to 1.3.6.4
Fixed in:
1.3.6.5
Disclosed:
Mar 14, 2025

CVE-2025-26890 on NVD →

HUSKY – Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion

critical

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.6.5 via the 'template' parameter of the woof_text_search AJAX action. This makes it possible for unauthenticated attackers to include and execute arbitrary files...

CVSS:
9.8
Affected:
up to 1.3.6.5
Fixed in:
1.3.6.6
Disclosed:
Mar 10, 2025

CVE-2025-1661 on NVD →

HUSKY &#8211; Products Filter Professional for WooCommerce [woocommerce-products-filter] < 1.3.4.3 (closed)

unknown

[en] Missing Authorization vulnerability in realmag777 HUSKY allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HUSKY: from n/a through 1.3.4.2.

Affected:
up to 1.3.4.3
Fixed in:
1.3.4.3
Disclosed:
Dec 13, 2024

CVE-2023-40334 on NVD →

HUSKY – Products Filter for WooCommerce <= 1.3.6.3 - Reflected Cross-Site Scripting via really_curr_tax Parameter

medium

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the really_curr_tax parameter in all versions up to, and including, 1.3.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers t...

CVSS:
6.1
Affected:
up to 1.3.6.3
Fixed in:
1.3.6.4
Disclosed:
Nov 19, 2024

CVE-2024-11400 on NVD →

HUSKY &#8211; Products Filter Professional for WooCommerce [woocommerce-products-filter] < 1.3.6.4 (closed)

unknown

[en] The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the really_curr_tax parameter in all versions up to, and including, 1.3.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attack...

Affected:
up to 1.3.6.4
Fixed in:
1.3.6.4
Disclosed:
Nov 19, 2024

CVE-2024-11400 on NVD →

HUSKY &#8211; Products Filter Professional for WooCommerce [woocommerce-products-filter] < 1.3.6.2 (closed)

unknown

[en] The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.6.1 via the woof_messenger_remove_subscr AJAX action due to missing validation on the 'key' user controlled key. This makes it possible for authe...

Affected:
up to 1.3.6.2
Fixed in:
1.3.6.2
Disclosed:
Sep 25, 2024

CVE-2024-7491 on NVD →

HUSKY – Products Filter Professional for WooCommerce <= 1.3.6.1 - Insecure Direct Object Reference to Unsubscribe

medium

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.6.1 via the woof_messenger_remove_subscr AJAX action due to missing validation on the 'key' user controlled key. This makes it possible for authentica...

CVSS:
5.3
Affected:
up to 1.3.6.1
Fixed in:
1.3.6.2
Disclosed:
Sep 24, 2024

CVE-2024-7491 on NVD →

HUSKY &#8211; Products Filter Professional for WooCommerce [woocommerce-products-filter] < 1.3.6.2 (closed)

unknown

[en] Improper Privilege Management vulnerability in realmag777 HUSKY allows Privilege Escalation.This issue affects HUSKY: from n/a through 1.3.6.1.

Affected:
up to 1.3.6.2
Fixed in:
1.3.6.2
Disclosed:
Aug 13, 2024

CVE-2024-43121 on NVD →

HUSKY <= 1.3.6.1 - Authenticated (Shop Manager+) Arbitrary Options Update

high

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to missing option validation on the do_import_data() function in all versions up to, and including, 1.3.6.1. This makes it possible for authenticated...

CVSS:
7.2
Affected:
up to 1.3.6.1
Fixed in:
1.3.6.2
Disclosed:
Aug 7, 2024

CVE-2024-43121 on NVD →

HUSKY &#8211; Products Filter Professional for WooCommerce [woocommerce-products-filter] < 1.3.6.1 (closed)

unknown

[en] The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the ‘woof_author’ parameter in all versions up to, and including, 1.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL quer...

Affected:
up to 1.3.6.1
Fixed in:
1.3.6.1
Disclosed:
Jul 16, 2024

CVE-2024-6457 on NVD →

HUSKY - Products Filter Professional for WooCommerce <= 1.3.6 - Unauthenticated Time-Based SQL Injection

critical

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the ‘woof_author’ parameter in all versions up to, and including, 1.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. T...

CVSS:
9.8
Affected:
up to 1.3.6
Fixed in:
1.3.6.1
Disclosed:
Jul 15, 2024

CVE-2024-6457 on NVD →

HUSKY &#8211; Products Filter Professional for WooCommerce [woocommerce-products-filter] < 1.3.6 (closed)

unknown

[en] The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.3.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for a...

Affected:
up to 1.3.6
Fixed in:
1.3.6
Disclosed:
May 29, 2024

CVE-2024-5039 on NVD →

HUSKY – Products Filter Professional for WooCommerce <= 1.3.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.3.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authen...

CVSS:
6.4
Affected:
up to 1.3.5.3
Fixed in:
1.3.6
Disclosed:
May 28, 2024

CVE-2024-5039 on NVD →

HUSKY &#8211; Products Filter Professional for WooCommerce [woocommerce-products-filter] < 1.3.5.3 (closed)

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Control of Generation of Code ('Code Injection') vulnerability in PluginUS HUSKY – Products Filter for WooCommerce (formerly WOOF) allows Using Malicious Files, Code Inclusion.This issue affects HUSKY – Products Filter for Woo...

Affected:
up to 1.3.5.3
Fixed in:
1.3.5.3
Disclosed:
May 17, 2024

CVE-2024-32680 on NVD →

HUSKY – Products Filter for WooCommerce (formerly WOOF) <= 1.3.5.2 - Authenticated (Subscriber+) Remote Code Execution

critical

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.5.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute code on the server.

CVSS:
9.9
Affected:
up to 1.3.5.2
Fixed in:
1.3.5.3
Disclosed:
Apr 17, 2024

CVE-2024-32680 on NVD →

HUSKY &#8211; Products Filter Professional for WooCommerce [woocommerce-products-filter] < 1.3.5.2 (closed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in realmag777 HUSKY – Products Filter for WooCommerce (formerly WOOF).This issue affects HUSKY – Products Filter for WooCommerce (formerly WOOF): from n/a through 1.3.5.1.

Affected:
up to 1.3.5.2
Fixed in:
1.3.5.2
Disclosed:
Mar 29, 2024

CVE-2024-30462 on NVD →

HUSKY &#8211; Products Filter Professional for WooCommerce [woocommerce-products-filter] < 1.3.5.3 (closed)

unknown

[en] The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.5.2 via the 'type' parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to include and execute arbitrary...

Affected:
up to 1.3.5.3
Fixed in:
1.3.5.3
Disclosed:
Mar 29, 2024

CVE-2024-3061 on NVD →

HUSKY – Products Filter Professional for WooCommerce <= 1.3.5.2 - Authenticated (Admin+) Local File Inclusion

high

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.5.2 via the 'type' parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to include and execute arbitrary file...

CVSS:
7.2
Affected:
up to 1.3.5.2
Fixed in:
1.3.5.3
Disclosed:
Mar 28, 2024

CVE-2024-3061 on NVD →

HUSKY – Products Filter for WooCommerce (formerly WOOF) <= 1.3.5.1 - Cross-Site Request Forgery

medium

The HUSKY – Products Filter for WooCommerce (formerly WOOF) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.5.1. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to perform unauthorized...

CVSS:
4.3
Affected:
up to 1.3.5.1
Fixed in:
1.3.5.2
Disclosed:
Mar 28, 2024

CVE-2024-30462 on NVD →

HUSKY &#8211; Products Filter Professional for WooCommerce [woocommerce-products-filter] < 1.3.4.4 (closed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in realmag777 HUSKY – Products Filter for WooCommerce (formerly WOOF).This issue affects HUSKY – Products Filter for WooCommerce (formerly WOOF): from n/a through 1.3.4.3.

Affected:
up to 1.3.4.4
Fixed in:
1.3.4.4
Disclosed:
Mar 15, 2024

CVE-2023-50861 on NVD →

HUSKY &#8211; Products Filter Professional for WooCommerce [woocommerce-products-filter] < 1.3.5.2 (closed)

unknown

[en] The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'woof' shortcode in all versions up to, and including, 1.3.5.1 due to insufficient input sanitization and output escaping on user supplied attributes such as 'swoof_slug'. Thi...

Affected:
up to 1.3.5.2
Fixed in:
1.3.5.2
Disclosed:
Mar 15, 2024

CVE-2024-1796 on NVD →

HUSKY &#8211; Products Filter Professional for WooCommerce [woocommerce-products-filter] < 1.3.5.3 (closed)

unknown

[en] The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerable to SQL Injection via the 'name' parameter in the woof shortcode in all versions up to, and including, 1.3.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQ...

Affected:
up to 1.3.5.3
Fixed in:
1.3.5.3
Disclosed:
Mar 15, 2024

CVE-2024-1795 on NVD →

HUSKY – Products Filter for WooCommerce Professional <= 1.3.5.2 - Authenticated (Contributor+) SQL Injection

high

The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerable to SQL Injection via the 'name' parameter in the woof shortcode in all versions up to, and including, 1.3.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL que...

CVSS:
8.8
Affected:
up to 1.3.5.2
Fixed in:
1.3.5.3
Disclosed:
Mar 14, 2024

CVE-2024-1795 on NVD →

HUSKY – Products Filter for WooCommerce Professional <= 1.3.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'woof' shortcode in all versions up to, and including, 1.3.5.1 due to insufficient input sanitization and output escaping on user supplied attributes such as 'swoof_slug'. This mak...

CVSS:
6.4
Affected:
up to 1.3.5.1
Fixed in:
1.3.5.2
Disclosed:
Mar 14, 2024

CVE-2024-1796 on NVD →

HUSKY – Products Filter for WooCommerce (formerly WOOF) <= 1.3.4.3 - Cross-Site Request Forgery

medium

The HUSKY – Products Filter for WooCommerce (formerly WOOF) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.4.3. This is due to missing or incorrect nonce validation on several functions in the ext/stat/index.php file. This makes it possible for unauthenticated att...

CVSS:
4.3
Affected:
up to 1.3.4.3
Fixed in:
1.3.4.4
Disclosed:
Dec 22, 2023

CVE-2023-50861 on NVD →

HUSKY &#8211; Products Filter Professional for WooCommerce [woocommerce-products-filter] < 1.3.4.3 (closed)

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in realmag777 HUSKY – Products Filter for WooCommerce Professional.This issue affects HUSKY – Products Filter for WooCommerce Professional: from n/a through 1.3.4.2.

Affected:
up to 1.3.4.3
Fixed in:
1.3.4.3
Disclosed:
Dec 20, 2023

CVE-2023-40010 on NVD →

HUSKY – Products Filter for WooCommerce (formerly WOOF) <= 1.3.4.2 - Unauthenticated SQL Injection via search terms

critical

The HUSKY – Products Filter for WooCommerce (formerly WOOF) plugin for WordPress is vulnerable to generic SQL Injection via search terms in versions up to, and including, 1.3.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it poss...

CVSS:
9.8
Affected:
up to 1.3.4.2
Fixed in:
1.3.4.3
Disclosed:
Nov 27, 2023

CVE-2023-40010 on NVD →

HUSKY – Products Filter for WooCommerce (formerly WOOF) <= 1.3.4.2 - Missing Authorization via woof_meta_get_keys()

medium

The HUSKY – Products Filter for WooCommerce (formerly WOOF) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the woof_meta_get_keys() function in versions up to, and including, 1.3.4.2. This makes it possible for authenticated attackers, with contributor-level acces...

CVSS:
4.3
Affected:
up to 1.3.4.2
Fixed in:
1.3.4.3
Disclosed:
Nov 23, 2023

CVE-2023-40334 on NVD →

HUSKY &#8211; Products Filter Professional for WooCommerce [woocommerce-products-filter] < 1.3.2 (closed)

unknown

[en] The HUSKY WordPress plugin before 1.3.2 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.

Affected:
up to 1.3.2
Fixed in:
1.3.2
Disclosed:
Feb 6, 2023

CVE-2022-4489 on NVD →

HUSKY – Products Filter for WooCommerce Professional <= 1.3.1 - Authenticated (Admin+) PHP Object Injection

high

The HUSKY plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.3.1 via deserialization of untrusted input in the get_all_options function. This allows authenticated attackers with administrator-level privileges to inject a PHP Object. No POP chain is present in the vulnerable...

CVSS:
7.2
Affected:
up to 1.3.1
Fixed in:
1.3.2
Disclosed:
Jan 11, 2023

CVE-2022-4489 on NVD →

HUSKY &#8211; Products Filter Professional for WooCommerce [woocommerce-products-filter] < 1.2.6.3 (closed)

unknown

[en] The WOOF WordPress plugin before 1.2.6.3 does not sanitise and escape the woof_redraw_elements before outputing back in an admin page, leading to a Reflected Cross-Site Scripting

Affected:
up to 1.2.6.3
Fixed in:
1.2.6.3
Disclosed:
Feb 1, 2022

CVE-2021-25085 on NVD →

WOOF - Products Filter for WooCommerce <= 1.2.6.2 - Reflected Cross-Site Scripting

medium

The WOOF WordPress plugin before 1.2.6.3 does not sanitise and escape the woof_redraw_elements before outputing back in an admin page, leading to a Reflected Cross-Site Scripting

CVSS:
6.1
Affected:
up to 1.2.6.3
Fixed in:
1.2.6.3
Disclosed:
Dec 28, 2021

CVE-2021-25085 on NVD →

HUSKY &#8211; Products Filter Professional for WooCommerce [woocommerce-products-filter] < 2.2.0 (closed)

unknown

[en] A local file inclusion issue was discovered in the WooCommerce Products Filter (aka WOOF) plugin before 2.2.0 for WordPress, as demonstrated by the shortcode parameter in a woof_redraw_woof action. The vulnerability is due to the lack of args/input validation on render_html before allowing it to be called by extra...

Affected:
up to 2.2.0
Fixed in:
2.2.0
Disclosed:
Mar 14, 2018

CVE-2018-8711 on NVD →

HUSKY &#8211; Products Filter Professional for WooCommerce [woocommerce-products-filter] < 1.2.0 (closed)

unknown

[en] A remote code execution issue was discovered in the WooCommerce Products Filter (aka WOOF) plugin before 2.2.0 for WordPress, as demonstrated by the shortcode parameter in a woof_redraw_woof action. The plugin implemented a page redraw AJAX function accessible to anyone without any authentication. WordPress shortc...

Affected:
up to 1.2.0
Fixed in:
1.2.0
Disclosed:
Mar 14, 2018

CVE-2018-8710 on NVD →

WOOF - Products Filter for WooCommerce <= 1.1.9 - Remote Code Execution

critical

A remote code execution issue was discovered in the WooCommerce Products Filter (aka WOOF) plugin before 1.2.0 for WordPress, as demonstrated by the shortcode parameter in a woof_redraw_woof action. The plugin implemented a page redraw AJAX function accessible to anyone without any authentication. WordPress shortcode m...

CVSS:
9.8
Affected:
up to 1.2.0
Fixed in:
1.2.0
Disclosed:
Mar 6, 2018

CVE-2018-8710 on NVD →

WOOF - Products Filter for WooCommerce <= 1.1.9 - Local File Inclusion

critical

A local file inclusion issue was discovered in the WooCommerce Products Filter (aka WOOF) plugin before 1.2.0 for WordPress, as demonstrated by the shortcode parameter in a woof_redraw_woof action. The vulnerability is due to the lack of args/input validation on render_html before allowing it to be called by extract(),...

CVSS:
9.8
Affected:
up to 1.2.0
Fixed in:
1.2.0
Disclosed:
Mar 6, 2018

CVE-2018-8711 on NVD →

HUSKY &#8211; Products Filter Professional for WooCommerce [woocommerce-products-filter] < 1.1.5 (closed)

unknown

WordPress WooCommerce Products Filter plugin is prone to Authenticated Persistent Cross-Site Scripting (XSS) Vulnerability. The settingsa re saved without sanitization and “default_overlay_skin_word” is shown on the front-end pages without escaping it. Update the plugin.

Affected:
up to 1.1.5
Fixed in:
1.1.5
Disclosed:
Jul 8, 2017

HUSKY &#8211; Products Filter Professional for WooCommerce [woocommerce-products-filter] < 1.1.5 (closed)

unknown

WordPress WooCommerce Products Filter is prone to An Arbitrary File Upload Vulnerability. The file /lib/simple-ajax-uploader/action.php doesn't do any validation who can access the upload functionality. Update the plugin.

Affected:
up to 1.1.5
Fixed in:
1.1.5
Disclosed:
Jul 8, 2017

HUSKY &#8211; Products Filter Professional for WooCommerce [woocommerce-products-filter] < 1.3.6.6 (closed)

unknown
Affected:
up to 1.3.6.6
Fixed in:
1.3.6.6

CVE-2025-1661 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database