Access violation vulnerability in HUSKY – Products Filter Professional for WooCommerce 1.3.6.5

A plugin called HUSKY – Products Filter Professional for WooCommerce on WordPress has a security issue in all versions up to 1.3.6.5. This allows anyone to access and run any files on the server without authorization by using the ‘template’ parameter of the woof_text_search AJAX action. This can lead to bypassing security measures, accessing private information, and running malicious code. This vulnerability can be exploited even if the files are considered safe to upload, such as images.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.