Description
Path Traversal: '.../...//' vulnerability in Trusty Plugins Shop Products Filter trusty-woo-products-filter allows PHP Local File Inclusion.This issue affects Shop Products Filter: from n/a through <= 1.2.
Published: 2025-04-11
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Trusty Plugins Shop Products Filter is vulnerable to a Path Traversal flaw that allows PHP Local File Inclusion. The flaw permits an attacker to supply a specially crafted file path that can resolve outside the intended directory, permitting the inclusion of any accessible file on the server. If an attacker can include configuration files or code, they may disclose sensitive information or trigger remote code execution. The weakness is cataloged as CWE‑35.

Affected Systems

The vulnerability affects the Trusty Plugins Shop Products Filter plugin for WordPress, specifically any installation of version 1.2 or earlier. Any website that has this plugin deployed without a recent upgrade is potentially impacted, regardless of the site’s overall WordPress version. No specific server OS or PHP version is listed as a requirement in the advisory.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity of the flaw. The EPSS score of less than 1% shows a very low current exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is through a web interface that accepts user-controlled input; the vulnerability is inferred to be exploitable by an unauthenticated attacker who can issue crafted requests to the plugin’s endpoint. While no remote code execution is formally documented, the ability to include arbitrary files means this risk exists if sensitive files are readable or if code files can be injected.

Generated by OpenCVE AI on April 30, 2026 at 23:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Trusty Plugins Shop Products Filter plugin to the latest version (1.3 or higher).
  • If an immediate update is not feasible, uninstall or disable the plugin until the patch can be applied.
  • Deploy a web application firewall rule that blocks or logs requests containing path traversal sequences such as "../" or repeated directory separators.

Generated by OpenCVE AI on April 30, 2026 at 23:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-10766 Path Traversal vulnerability in Trusty Plugins Shop Products Filter allows PHP Local File Inclusion. This issue affects Shop Products Filter: from n/a through 1.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Path Traversal vulnerability in Trusty Plugins Shop Products Filter allows PHP Local File Inclusion. This issue affects Shop Products Filter: from n/a through 1.2. Path Traversal: '.../...//' vulnerability in Trusty Plugins Shop Products Filter trusty-woo-products-filter allows PHP Local File Inclusion.This issue affects Shop Products Filter: from n/a through <= 1.2.
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Fri, 11 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Apr 2025 09:00:00 +0000

Type Values Removed Values Added
Description Path Traversal vulnerability in Trusty Plugins Shop Products Filter allows PHP Local File Inclusion. This issue affects Shop Products Filter: from n/a through 1.2.
Title WordPress Shop Products Filter Plugin <= 1.2 - Local File Inclusion vulnerability
Weaknesses CWE-35
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:24.903Z

Reserved: 2025-04-09T11:20:15.875Z

Link: CVE-2025-32585

cve-icon Vulnrichment

Updated: 2025-04-11T13:54:00.659Z

cve-icon NVD

Status : Deferred

Published: 2025-04-11T09:15:29.607

Modified: 2026-04-23T15:29:09.480

Link: CVE-2025-32585

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T23:15:05Z

Weaknesses