Vulnerabilities / HUSKY / WPSEC-2026-0694

HUSKY <= 1.4.2 - Unauthenticated Reflected Cross-Site Scripting via 'woof_text' Parameter

Medium 6.1 CWE-79Fixed in 1.4.5
ID
WPSEC-2026-0694
Plugin
HUSKY – Products Filter for WooCommerce Professional (woocommerce-products-filter)
Affected
all versions before 1.4.5
Remediation
Update to 1.4.5 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness
CWE-79
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-10
Attack surface
HUSKY on WPSec AttackSurface
Fix released
Published

Description

The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'woof_text' parameter (text search label) in all versions up to, and including, 1.4.2. This is due to the HTML-escaped search text being placed into the woof_ext_filter_titles data passed to wp_localize_script(), which decodes HTML entities, so the escaping is undone and the text is later rendered as HTML by the front-end filter script. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into clicking a crafted link.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0