Junglewise Threat Intelligence

CVE-2020-37174: RealMag777 WOOF Products Filter for WooCommerce persistent XSS

CVE-2020-37174 · Severity: medium · CVSS 5.5 · Published 2026-05-13

Vendors: RealMag777.

Executive brief

The WOOF Products Filter for WooCommerce plugin (now known as HUSKY) contains a security flaw that allows authorized users with administrative access to inject malicious scripts into the website's settings. These scripts are saved permanently and will execute in the browsers of any visitor who views the store's product pages. This could lead to unauthorized actions being performed on behalf of visitors or the redirection of customers to malicious websites.

Technical details

A persistent cross-site scripting (XSS) vulnerability exists in the WOOF Products Filter for WooCommerce plugin (version 1.2.3 and potentially earlier). The vulnerability is located in the 'Design' tab of the plugin settings, specifically within text fields such as 'Text for block toggle' and 'Custom front css styles'. An authenticated attacker with high privileges (e.g., an administrator) can input malicious JavaScript payloads into these fields. Because the input is not properly sanitized before being stored and subsequently rendered on the frontend, the script executes in the context of any user visiting the shop pages. This can be used to hijack user sessions or perform unauthorized actions on the site.

Affected products

  • RealMag777 WOOF Products Filter for WooCommerce (HUSKY) 1.2.3 and earlier

Timeline

  • 2020-02-15: disclosed: Initial discovery and exploit published by researcher Shahab.ra.9
  • 2026-05-13: advisory: CVE published/updated via VulnCheck and NVD

References