Impact
The Product Filter for WooCommerce by WBW plugin is vulnerable to reflected cross‑site scripting when the attacker supplies an unsanitized value for the 'wpf_fid' parameter. This flaw allows the injection of arbitrary JavaScript into pages that display the resulting filter output. The injected script runs in the context of the site and is executed when a user visits a crafted URL containing the malicious parameter.
Affected Systems
WordPress installations that include the Product Filter for WooCommerce by WBW plugin with versions up to and including 3.4.2 are affected. The vulnerability is present in all releases of the plugin up to 3.4.2 regardless of active theme, other plugins, or whether the filter page is public or restricted.
Risk and Exploitability
The CVSS score of 6.1 indicates medium severity. Exploitation requires an attacker to create a URL containing a malicious 'wpf_fid' value and convince a user to click it; thus the attack vector is user interaction via a link. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The impact is limited to the user who visits the crafted link, but the potential consequences depend on the content of the injected script and are unpredictable.
OpenCVE Enrichment