WOOF Products Filter
cpe:2.3:a:pluginus:woocommerce_products_filter:*:*:*:*:wordpress:*:*
- <= 1.2.3
A persistent cross-site scripting vulnerability has been identified in WOOF Products Filter for WooCommerce version 1.2.3. This vulnerability allows authenticated attackers to inject malicious scripts into the 'Text for block toggle' and 'Custom front CSS styles' fields within the design tab. The injected JavaScript executes on the frontend, impacting all site visitors.
Exploitation of this vulnerability allows for persistent cross-site scripting, where injected scripts are executed in the context of the user viewing the affected page.
To reproduce this vulnerability, navigate to the WordPress admin panel and go to the WooCommerce Products Filter settings. In the 'Design' tab, enter a script payload into the 'Text for block toggle' and 'Custom front CSS styles' fields. After saving the changes, the injected script will execute on the frontend of the site.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.