Executive brief
The Themify WooCommerce Product Filter is a WordPress plugin that helps online stores filter products during shopping. An unauthenticated attacker can inject malicious JavaScript code by crafting a malicious link—if a shopper clicks the link, the code executes in their browser and could steal their session, inject fake content, or perform actions on their behalf. No authentication is required for this attack.
Technical details
This is a reflected cross-site scripting (XSS) vulnerability in the Themify WooCommerce Product Filter plugin caused by insufficient input sanitization and output escaping of query parameter names. An unauthenticated attacker can inject arbitrary JavaScript through a specially crafted URL parameter, which is then reflected in the page output without proper sanitization. The attack requires social engineering (tricking a user to click a link) to succeed, but once triggered, arbitrary JavaScript executes in the victim's browser session. The vulnerability affects all versions up to and including 1.5.5; patches should be available from the plugin developers.
Affected products
- Themify WooCommerce Product Filter up to 1.5.5
Timeline
- 2026-09-11: disclosed