Executive brief
The Product Filter for WooCommerce by WBW is a WordPress plugin that allows customers to filter product listings on e-commerce sites. An unauthenticated attacker can inject malicious JavaScript into pages by crafting a specially designed link and tricking users into clicking it. Successful exploitation can steal customer session data, redirect users to phishing sites, or deface the store front.
Technical details
This is a reflected cross-site scripting (XSS) vulnerability in the WBW Product Filter for WooCommerce plugin. The vulnerability exists in the 'wpf_fid' parameter due to insufficient input sanitization and output escaping. An unauthenticated attacker can inject arbitrary JavaScript code that executes in the victim's browser when a user clicks on a malicious link, provided the page uses the vulnerable filter recalculation output. No authentication is required, and the attack vector is network-based via crafted URLs.
Affected products
- WBW Product Filter for WooCommerce up to and including 3.4.2
Timeline
- 2026-09-09: disclosed