Impact
The HUSKY – Products Filter Professional plugin is vulnerable to a reflected cross‑site scripting flaw triggered through SEO‑friendly permalink segments in the URL. The vulnerability arises because the wp_load_js() function reads filter values directly from the URL path, then embeds those values into an inline JavaScript string via json_encode() without properly escaping single quotes. As a result, an attacker can include a specially crafted URL that injects arbitrary script code into a page viewed by any user who follows the link.
Affected Systems
WordPress sites running the realmag777 HUSKY – Products Filter Professional plugin, versions 1.4.3 and earlier.
Risk and Exploitability
The flaw carries a CVSS score of 6.1 and is not currently listed in the CISA KEV catalog. Exploitation requires the attacker to send a malicious URL to a target user; if the victim clicks the link, the embedded script executes in the victim’s browser, permitting data theft or session hijacking. Because the attack vector is a crafted link that can be publicly shared, the condition is widely exploitable without authentication, even though the plugin itself is functional for all users.
OpenCVE Enrichment