Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginUs.Net HUSKY woocommerce-products-filter allows Reflected XSS.This issue affects HUSKY: from n/a through 1.4.3.2.
Published: 2026-10-09
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Cross-site scripting
Action: Patch
AI Analysis

Impact

The vulnerability is an improper neutralization of input during web page generation, resulting in a reflected XSS in the HUSKY Woocommerce‑Products‑Filter plugin. An attacker can inject script payloads that execute in the browsers of users who view reflected data, potentially allowing the attacker to capture sensitive information or perform actions on behalf of the user. This weakness is classified as CWE‑79.

Affected Systems

PluginUs.Net’s HUSKY Woocommerce‑Products‑Filter plugin, all releases up to version 1.4.3.2 are affected; newer releases are believed to be fixed.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity. The EPSS score is not available, so the exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a crafted HTTP request to the WordPress site that includes attacker-supplied input; because the input is reflected without proper escaping, a browser executing the page will run the injected script.

Generated by OpenCVE AI on October 9, 2026 at 12:09 UTC.

Remediation

Vendor Solution

Update the WordPress HUSKY plugin to the latest available version (at least 1.4.4).


OpenCVE Recommended Actions

  • Upgrade the HUSKY plugin to version 1.4.4 or later.
  • If an immediate upgrade is not possible, disable or remove the plugin until a patch is applied.
  • Implement a content security policy that restricts inline scripts to mitigate the impact of any residual reflected XSS.
  • Ensure that all user inputs processed by the plugin are properly sanitized or validated.

Generated by OpenCVE AI on October 9, 2026 at 12:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 10:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginUs.Net HUSKY woocommerce-products-filter allows Reflected XSS.This issue affects HUSKY: from n/a through 1.4.3.2.
Title WordPress HUSKY plugin <= 1.4.3.2 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-09T10:00:18.049Z

Reserved: 2026-09-22T09:18:20.380Z

Link: CVE-2026-95608

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T10:16:43.053

Modified: 2026-10-09T10:16:43.053

Link: CVE-2026-95608

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T12:15:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')