CVE · Medium

CVE-2025-13109 — HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.7.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-13109 HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.7.3 Authorization Bypass Through User-Controlled Key Medium 4.3 < 1.3.7.3 1.3.7.3 2025-12-03

CVE-2025-13109

The HUSKY – Products Filter Professional plugin for WooCommerce has a security flaw in all versions up to 1.3.7.2 that allows an attacker with at least subscriber-level access to manipulate another user's saved searches by exploiting a missing check on a variable passed through the "woof_add_query" and "woof_remove_query" functions. This vulnerability enables attackers to insert or delete search queries in any user's profile, including administrators', without proper authorization.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.