Impact
The vulnerability in the Themify – WooCommerce Product Filter plugin allows an attacker to inject malicious JavaScript into a page through a reflected cross‑site scripting flaw. The flaw originates from insufficient input sanitization and output escaping of a query parameter name. If an attacker sends a specially crafted URL to a victim, the victim’s browser executes the injected script in the context of the site, potentially leading to credential theft, session hijacking, or defacement. This weakness is identified as CWE‑79.
Affected Systems
The defect exists in all supported releases of the plugin up to and including version 1.5.5. Any installation of the Themify – WooCommerce Product Filter plugin that has not been upgraded beyond 1.5.5 is susceptible.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity; the vulnerability is exploitable by unauthenticated attackers without local access. Because it relies on a crafted URL that a victim must click, the threat is limited to phishing or social engineering tactics. The EPSS score is not available and the issue is not listed in the CISA KEV catalog, suggesting no publicly known active exploits at the time of reporting. Nonetheless, the attack vector is straightforward and does not require advanced skills, so timely remediation is recommended.
OpenCVE Enrichment