Description
The Filter Everything — WordPress & WooCommerce Filters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.9.6. This is due to insufficient input sanitization and output escaping in the flrt_elementor_load_more_anchor() function. The function reads query parameters from $_SERVER['REQUEST_URI'] via getFormActionOrFullPageUrl(true), which URL-decodes them through parse_str() and re-assembles them using build_query() — a WordPress core function that does NOT re-encode values ($urlencode=false). The resulting URL, containing unescaped special characters, is injected into a data-next-page HTML attribute via preg_replace() without esc_attr() or esc_url(). This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link.
Published: 2026-10-10
Score: 6.1 Medium
EPSS: n/a
KEV: No
Impact: Reflected Cross‑Site Scripting
Action: Update Plugin
AI Analysis

Impact

The Filter Everything plugin contains a reflected XSS flaw caused by inadequate sanitization of URL query parameters in the flrt_elementor_load_more_anchor function. When a crafted URL is processed, the plugin assembles the parameters into a data‑next‑page attribute without encoding, enabling the injection of arbitrary JavaScript. This flaw allows an unauthenticated attacker to execute script code in the victim’s browser when the victim follows a malicious link.

Affected Systems

WordPress sites that use the Filter Everything ‑ WordPress & WooCommerce Filters plugin in any version up to and including 1.9.6. The vulnerability exists within the flrt_elementor_load_more_anchor portion of the plugin files.

Risk and Exploitability

The CVSS score of 6.1 denotes a medium severity for unauthenticated attackers. Because the flaw is reflected, an attacker only needs open a crafted URL; no authentication or advanced capabilities are required. This user‑interaction requirement makes the vulnerability less dangerous than a remote code execution flaw but still hazardous—malicious scripts can steal cookies, deface the site, or redirect victims. The EPSS value is unknown, and the vulnerability is not included in the CISA KEV catalogue, indicating no confirmed exploits at this time. The likely attack vector is a crafted link that a victim follows, which the plugin processes and injects; this inference is based on the description.

Generated by OpenCVE AI on October 10, 2026 at 05:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Filter Everything plugin to the latest release that removes the reflectable input handling.
  • If an upgrade is not possible immediately, disable or uninstall the plugin to remove the exposed entry point.
  • If you can patch the plugin source, modify the code to escape query parameter values with esc_attr() or esc_url() before inserting them into the data-next-page attribute.

Generated by OpenCVE AI on October 10, 2026 at 05:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 04:30:00 +0000

Type Values Removed Values Added
Description The Filter Everything — WordPress & WooCommerce Filters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.9.6. This is due to insufficient input sanitization and output escaping in the flrt_elementor_load_more_anchor() function. The function reads query parameters from $_SERVER['REQUEST_URI'] via getFormActionOrFullPageUrl(true), which URL-decodes them through parse_str() and re-assembles them using build_query() — a WordPress core function that does NOT re-encode values ($urlencode=false). The resulting URL, containing unescaped special characters, is injected into a data-next-page HTML attribute via preg_replace() without esc_attr() or esc_url(). This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link.
Title Filter Everything — WordPress & WooCommerce Filters <= 1.9.6 - Reflected Cross-Site Scripting via Elementor Posts Widget Pagination URL
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T04:26:45.199Z

Reserved: 2026-09-09T13:22:17.653Z

Link: CVE-2026-87869

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T05:16:40.277

Modified: 2026-10-10T05:16:40.277

Link: CVE-2026-87869

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T06:00:12Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')