WOOF Products Filter for WooCommerce Persistent Cross-Site Scripting Vulnerability

Vulnerability

A persistent cross-site scripting vulnerability has been identified in WOOF Products Filter for WooCommerce version 1.2.3. This vulnerability allows authenticated attackers to inject malicious scripts into the 'Text for block toggle' and 'Custom front CSS styles' fields within the design tab. The injected JavaScript executes on the frontend, impacting all site visitors.

Impact

Exploitation of this vulnerability allows for persistent cross-site scripting, where injected scripts are executed in the context of the user viewing the affected page.

Reproduction

To reproduce this vulnerability, navigate to the WordPress admin panel and go to the WooCommerce Products Filter settings. In the 'Design' tab, enter a script payload into the 'Text for block toggle' and 'Custom front CSS styles' fields. After saving the changes, the injected script will execute on the frontend of the site.

Added: May 13, 2026, 6:59 PM
Updated: May 13, 2026, 6:59 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
1.7
exploitability
6.5
remediation
0.0
relevance
8.2
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.