Executive brief
The Avalon23 Products Filter for WooCommerce plugin for WordPress, which helps online stores filter and display products, contains a security flaw. An attacker with basic contributor-level access can inject malicious scripts into website pages. These scripts will automatically run in the browser of any visitor who views the affected page, potentially leading to unauthorized actions or data theft.
Technical details
The Avalon23 Products Filter for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the 'avalon23_qr' shortcode. This vulnerability exists because the AVALON23_HELPER::draw_html_item() helper function fails to perform adequate input sanitization or output escaping on shortcode attributes like 'title' and 'fixed_link' before concatenating them into HTML attributes. An authenticated attacker with Contributor-level permissions or higher can exploit this by injecting malicious JavaScript into a page. The script executes in the context of any user's browser session when they visit the compromised page. The issue affects all versions up to and including 1.1.6.
Affected products
- paradigmatools Avalon23 Products Filter for WooCommerce <= 1.1.6
Timeline
- 2026-06-24: advisory: Advisory published by Wordfence and NVD
References
- https://plugins.trac.wordpress.org/browser/avalon23-products-filter-for-woocommerce/trunk/classes/helper.php
- https://plugins.trac.wordpress.org/browser/avalon23-products-filter-for-woocommerce/trunk/ext/qr_generator/index.php
- https://plugins.trac.wordpress.org/browser/avalon23-products-filter-for-woocommerce/trunk/ext/qr_generator/index.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/da9089a2-420f-4744-96d1-46c050a95328?source=cve