Impact
Untrusted input is echoed by the Advanced AJAX Product Filters plugin without proper sanitization, allowing an unauthenticated actor to inject arbitrary JavaScript. Such malicious payloads can capture browser cookies, hijack user sessions, or deface content. The flaw does not grant arbitrary code execution but can lead to broader site compromise if attackers combine it with other weaknesses.
Affected Systems
All WordPress sites that use the BeRocket:Advanced AJAX Product Filters plugin version 3.2.0.3 or earlier are affected. No specific WordPress core version is mentioned, but the vulnerability exists regardless of core version as long as the plugin is installed and reachable.
Risk and Exploitability
Based on the description, it is inferred that the CVSS score of 7.1 classifies the flaw as high severity. Based on the description, it is inferred that the lack of authentication requirements and the public nature of the AJAX endpoint suggest a non‑trivial likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, but its potential to steal or manipulate user session data and deface the web interface makes it a valuable target for attackers. Exploitation can be achieved simply by visiting a crafted URL or submitting a malicious query through a browser or automated tool.
OpenCVE Enrichment