CVE · Critical

CVE-2023-40010 — HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.4.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-40010 HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.4.3 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Critical 9.3 < 1.3.4.3 1.3.4.3 2023-11-27

CVE-2023-40010

The HUSKY – Products Filter for WooCommerce plugin through version 1.3.4.2 allows unauthenticated attackers to inject arbitrary SQL code through search parameters because user input is not properly escaped and SQL queries are not adequately prepared. An attacker could exploit this vulnerability to execute malicious SQL commands and access sensitive data stored in the database.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.