Description
Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX Product Filters <= 3.2.0.3 versions.
Published: 2026-08-06
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Untrusted input is echoed by the Advanced AJAX Product Filters plugin without proper sanitization, allowing an unauthenticated actor to inject arbitrary JavaScript. Such malicious payloads can capture browser cookies, hijack user sessions, or deface content. The flaw does not grant arbitrary code execution but can lead to broader site compromise if attackers combine it with other weaknesses.

Affected Systems

All WordPress sites that use the BeRocket:Advanced AJAX Product Filters plugin version 3.2.0.3 or earlier are affected. No specific WordPress core version is mentioned, but the vulnerability exists regardless of core version as long as the plugin is installed and reachable.

Risk and Exploitability

Based on the description, it is inferred that the CVSS score of 7.1 classifies the flaw as high severity. Based on the description, it is inferred that the lack of authentication requirements and the public nature of the AJAX endpoint suggest a non‑trivial likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, but its potential to steal or manipulate user session data and deface the web interface makes it a valuable target for attackers. Exploitation can be achieved simply by visiting a crafted URL or submitting a malicious query through a browser or automated tool.

Generated by OpenCVE AI on August 6, 2026 at 16:11 UTC.

Remediation

Vendor Solution

Update the WordPress Advanced AJAX Product Filters Plugin to the latest available version (at least 3.2.1).


OpenCVE Recommended Actions

  • Update the WordPress Advanced AJAX Product Filters plugin to the latest available version (at least 3.2.1).
  • Remove or disable any custom code that passes unsanitized user input to the plugin’s AJAX endpoints.
  • Keep the WordPress core and other plugins updated to the latest secure releases to reduce the overall attack surface.

Generated by OpenCVE AI on August 6, 2026 at 16:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Berocket
Berocket advanced Ajax Product Filters
Wordpress
Wordpress wordpress
Vendors & Products Berocket
Berocket advanced Ajax Product Filters
Wordpress
Wordpress wordpress

Thu, 06 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX Product Filters <= 3.2.0.3 versions.
Title WordPress Advanced AJAX Product Filters plugin <= 3.2.0.3 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Berocket Advanced Ajax Product Filters
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-06T14:27:49.297Z

Reserved: 2026-07-27T09:00:18.436Z

Link: CVE-2026-66439

cve-icon Vulnrichment

Updated: 2026-08-06T16:50:18.971Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T17:00:10Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')