CVE Database /
CVE-2020-37174
CVE · Medium
CVE-2020-37174 — HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] <= 1.2.3 (unfixed)
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2020-37174
|
HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] <= 1.2.3 (unfixed) |
— |
Medium
5.5
|
< 1.2.3
|
1.2.3 |
2026-05-13 |
—
|
CVE-2020-37174
The WOOF Products Filter for WooCommerce plugin through version 1.2.3 contains a stored cross-site scripting flaw that allows authenticated users to inject malicious JavaScript through design tab input fields, specifically the 'Text for block toggle' and 'Custom front css styles' settings. When these fields containing script payloads are saved, the injected code executes on the website frontend for all visitors. This vulnerability remains unfixed in the affected version and earlier releases.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings