Description
The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via Query Parameter Name in all versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Published: 2026-09-11
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Reflected cross‑site scripting that allows arbitrary script injection.
Action: Update plugin
AI Analysis

Impact

The vulnerability in the Themify – WooCommerce Product Filter plugin allows an attacker to inject malicious JavaScript into a page through a reflected cross‑site scripting flaw. The flaw originates from insufficient input sanitization and output escaping of a query parameter name. If an attacker sends a specially crafted URL to a victim, the victim’s browser executes the injected script in the context of the site, potentially leading to credential theft, session hijacking, or defacement. This weakness is identified as CWE‑79.

Affected Systems

The defect exists in all supported releases of the plugin up to and including version 1.5.5. Any installation of the Themify – WooCommerce Product Filter plugin that has not been upgraded beyond 1.5.5 is susceptible.

Risk and Exploitability

The CVSS score of 6.1 indicates moderate severity; the vulnerability is exploitable by unauthenticated attackers without local access. Because it relies on a crafted URL that a victim must click, the threat is limited to phishing or social engineering tactics. The EPSS score is not available and the issue is not listed in the CISA KEV catalog, suggesting no publicly known active exploits at the time of reporting. Nonetheless, the attack vector is straightforward and does not require advanced skills, so timely remediation is recommended.

Generated by OpenCVE AI on September 11, 2026 at 06:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the plugin to version 1.5.6 or later, which removes the query‑parameter sanitization flaw.
  • If an update is not immediately possible, manually modify the plugin’s source to sanitize the vulnerable query parameter before outputting it, ensuring proper escaping of all user‑controlled data.
  • Configure a web application firewall or host‑level security rule to block or sanitize attempts to inject JavaScript via the affected query parameter.

Generated by OpenCVE AI on September 11, 2026 at 06:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Themify
Themify woocommerce Product Filter
Wordpress
Wordpress wordpress
Vendors & Products Themify
Themify woocommerce Product Filter
Wordpress
Wordpress wordpress

Fri, 11 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Description The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via Query Parameter Name in all versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Title Themify – WooCommerce Product Filter <= 1.5.5 - Reflected Cross-Site Scripting
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Themify Woocommerce Product Filter
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-11T20:19:12.263Z

Reserved: 2026-08-23T14:49:36.284Z

Link: CVE-2026-78172

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-11T04:17:51.160

Modified: 2026-09-11T21:17:16.163

Link: CVE-2026-78172

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T19:15:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')