Description
The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via SEO-friendly permalink filter URL segments in versions up to, and including, 1.4.3. This is due to insufficient input sanitization and output escaping in the wp_load_js() function, which reads filter values from the URL path via the url_request extension's parse_url_query() and embeds them into an inline JavaScript string using json_encode() without escaping single quotes. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link.
Published: 2026-09-11
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Update
AI Analysis

Impact

The HUSKY – Products Filter Professional plugin is vulnerable to a reflected cross‑site scripting flaw triggered through SEO‑friendly permalink segments in the URL. The vulnerability arises because the wp_load_js() function reads filter values directly from the URL path, then embeds those values into an inline JavaScript string via json_encode() without properly escaping single quotes. As a result, an attacker can include a specially crafted URL that injects arbitrary script code into a page viewed by any user who follows the link.

Affected Systems

WordPress sites running the realmag777 HUSKY – Products Filter Professional plugin, versions 1.4.3 and earlier.

Risk and Exploitability

The flaw carries a CVSS score of 6.1 and is not currently listed in the CISA KEV catalog. Exploitation requires the attacker to send a malicious URL to a target user; if the victim clicks the link, the embedded script executes in the victim’s browser, permitting data theft or session hijacking. Because the attack vector is a crafted link that can be publicly shared, the condition is widely exploitable without authentication, even though the plugin itself is functional for all users.

Generated by OpenCVE AI on September 11, 2026 at 05:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the HUSKY plugin to the newest release (1.4.4 or later) which fixes the input sanitization and escaping flaw.
  • If a plugin upgrade cannot be applied immediately, disable or remove the SEO‑friendly permalink filter that exposes user‑controlled values in JavaScript output.
  • Implement a web application firewall rule or a strict content‑security‑policy header to block execution of injected scripts until a patch is applied.

Generated by OpenCVE AI on September 11, 2026 at 05:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Realmag777
Realmag777 husky – Products Filter For Woocommerce Professional
Wordpress
Wordpress wordpress
Vendors & Products Realmag777
Realmag777 husky – Products Filter For Woocommerce Professional
Wordpress
Wordpress wordpress

Sat, 12 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Description The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via SEO-friendly permalink filter URL segments in versions up to, and including, 1.4.3. This is due to insufficient input sanitization and output escaping in the wp_load_js() function, which reads filter values from the URL path via the url_request extension's parse_url_query() and embeds them into an inline JavaScript string using json_encode() without escaping single quotes. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link.
Title HUSKY <= 1.4.3 - Reflected Cross-Site Scripting
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Realmag777 Husky – Products Filter For Woocommerce Professional
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-11T16:04:49.511Z

Reserved: 2026-08-01T18:21:10.820Z

Link: CVE-2026-18562

cve-icon Vulnrichment

Updated: 2026-09-11T16:04:44.335Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T04:17:24.457

Modified: 2026-09-11T16:17:05.740

Link: CVE-2026-18562

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T19:56:58Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')