CVE · Critical

CVE-2018-8711 — HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 2.2.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2018-8711, CVE-2018-8710 HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 2.2.0 Improper Input Validation Critical 9.8 < 2.2.0 2.2.0 2018-03-06

CVE-2018-8711, CVE-2018-8710

The WooCommerce Products Filter plugin before version 2.2.0 contains a local file inclusion vulnerability in the woof_redraw_woof action handler. The flaw exists because the plugin fails to properly validate shortcode parameters before passing them to the extract() function, allowing an attacker to overwrite the $pagepath variable and include arbitrary local files on the server. This weakness could enable unauthorized access to sensitive files on the affected system.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.