HUSKY – Products Filter Professional for WooCommerce

Information

Software Type Plugin
Software Slug woocommerce-products-filter (view on wordpress.org)
Software Status Active
Software Author realmag777
Software Website products-filter.com
Software Downloads 1,858,274
Software Active Installs 100,000
Software Record Last Updated December 4, 2024

17 Vulnerabilities

Title Status CVE ID CVSS Researchers Date
HUSKY – Products Filter for WooCommerce <= 1.3.6.3 - Reflected Cross-Site Scripting via really_curr_tax Parameter Patched CVE-2024-11400 6.1 Daniel Scheidt November 19, 2024
HUSKY – Products Filter Professional for WooCommerce <= 1.3.6.1 - Insecure Direct Object Reference to Unsubscribe Patched CVE-2024-7491 5.3 shaman0x01 September 24, 2024
HUSKY <= 1.3.6.1 - Authenticated (Shop Manager+) Arbitrary Options Update Patched CVE-2024-43121 7.2 Rafie Muhammad August 7, 2024
HUSKY - Products Filter Professional for WooCommerce <= 1.3.6 - Unauthenticated Time-Based SQL Injection Patched CVE-2024-6457 9.8 Arkadiusz Hydzik July 15, 2024
HUSKY – Products Filter Professional for WooCommerce <= 1.3.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Patched CVE-2024-5039 6.4 Richard Telleng (stueotue) May 28, 2024
HUSKY – Products Filter for WooCommerce (formerly WOOF) <= 1.3.5.2 - Authenticated (Subscriber+) Remote Code Execution Patched CVE-2024-32680 9.9 beluga April 17, 2024
HUSKY – Products Filter for WooCommerce (formerly WOOF) <= 1.3.5.1 - Cross-Site Request Forgery Patched CVE-2024-30462 4.3 Dhabaleshwar Das March 28, 2024
HUSKY – Products Filter Professional for WooCommerce <= 1.3.5.2 - Authenticated (Admin+) Local File Inclusion Patched CVE-2024-3061 7.2 haidv35 March 28, 2024
HUSKY – Products Filter for WooCommerce Professional <= 1.3.5.2 - Authenticated (Contributor+) SQL Injection Patched CVE-2024-1795 8.8 Krzysztof Zając, Bassem Essam March 14, 2024
HUSKY – Products Filter for WooCommerce Professional <= 1.3.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Patched CVE-2024-1796 6.4 Bassem Essam March 14, 2024
HUSKY – Products Filter for WooCommerce (formerly WOOF) <= 1.3.4.3 - Cross-Site Request Forgery Patched CVE-2023-50861 4.3 Mika December 22, 2023
HUSKY – Products Filter for WooCommerce (formerly WOOF) <= 1.3.4.2 - Unauthenticated SQL Injection via search terms Patched CVE-2023-40010 9.8 Nguyen Anh Tien November 27, 2023
HUSKY – Products Filter for WooCommerce (formerly WOOF) <= 1.3.4.2 - Missing Authorization via woof_meta_get_keys() Patched CVE-2023-40334 4.3 thiennv November 23, 2023
HUSKY – Products Filter for WooCommerce Professional <= 1.3.1 - Authenticated (Admin+) PHP Object Injection Patched CVE-2022-4489 7.2 thinhnguyen1337 January 11, 2023
WOOF - Products Filter for WooCommerce <= 1.2.6.2 - Reflected Cross-Site Scripting Patched CVE-2021-25085 6.1 Krzysztof Zając December 28, 2021
WOOF - Products Filter for WooCommerce <= 1.1.9 - Local File Inclusion Patched CVE-2018-8711 9.8 March 6, 2018
WOOF - Products Filter for WooCommerce <= 1.1.9 - Remote Code Execution Patched CVE-2018-8710 9.8 March 6, 2018

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation