Impact
The Filter Everything plugin contains a reflected XSS flaw caused by inadequate sanitization of URL query parameters in the flrt_elementor_load_more_anchor function. When a crafted URL is processed, the plugin assembles the parameters into a data‑next‑page attribute without encoding, enabling the injection of arbitrary JavaScript. This flaw allows an unauthenticated attacker to execute script code in the victim’s browser when the victim follows a malicious link.
Affected Systems
WordPress sites that use the Filter Everything ‑ WordPress & WooCommerce Filters plugin in any version up to and including 1.9.6. The vulnerability exists within the flrt_elementor_load_more_anchor portion of the plugin files.
Risk and Exploitability
The CVSS score of 6.1 denotes a medium severity for unauthenticated attackers. Because the flaw is reflected, an attacker only needs open a crafted URL; no authentication or advanced capabilities are required. This user‑interaction requirement makes the vulnerability less dangerous than a remote code execution flaw but still hazardous—malicious scripts can steal cookies, deface the site, or redirect victims. The EPSS value is unknown, and the vulnerability is not included in the CISA KEV catalogue, indicating no confirmed exploits at this time. The likely attack vector is a crafted link that a victim follows, which the plugin processes and injects; this inference is based on the description.
OpenCVE Enrichment