Junglewise Threat Intelligence

CVE-2026-7804: WBW Product Filter for WooCommerce reflected XSS in wpf_fid parameter

CVE-2026-7804 · Severity: medium · CVSS 6.1 · Published 2026-09-09

Executive brief

The Product Filter for WooCommerce by WBW is a WordPress plugin that allows customers to filter product listings on e-commerce sites. An unauthenticated attacker can inject malicious JavaScript into pages by crafting a specially designed link and tricking users into clicking it. Successful exploitation can steal customer session data, redirect users to phishing sites, or deface the store front.

Technical details

This is a reflected cross-site scripting (XSS) vulnerability in the WBW Product Filter for WooCommerce plugin. The vulnerability exists in the 'wpf_fid' parameter due to insufficient input sanitization and output escaping. An unauthenticated attacker can inject arbitrary JavaScript code that executes in the victim's browser when a user clicks on a malicious link, provided the page uses the vulnerable filter recalculation output. No authentication is required, and the attack vector is network-based via crafted URLs.

Affected products

  • WBW Product Filter for WooCommerce up to and including 3.4.2

Timeline

  • 2026-09-09: disclosed

References