CVE · Medium

CVE-2020-37174 — HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] <= 1.2.3 (unfixed)

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2020-37174 HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] <= 1.2.3 (unfixed) Medium 5.5 < 1.2.3 1.2.3 2026-05-13

CVE-2020-37174

The WOOF Products Filter for WooCommerce plugin through version 1.2.3 contains a stored cross-site scripting flaw that allows authenticated users to inject malicious JavaScript through design tab input fields, specifically the 'Text for block toggle' and 'Custom front css styles' settings. When these fields containing script payloads are saved, the injected code executes on the website frontend for all visitors. This vulnerability remains unfixed in the affected version and earlier releases.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.