WP Clinic
Log in Sign up

CVE · Medium

CVE-2025-13109 — HUSKY – Products Filter Professional for WooCommerce [woocommerce-products-filter] < 1.3.7.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-13109 HUSKY – Products Filter Professional for WooCommerce [woocommerce-products-filter] < 1.3.7.3 Authorization Bypass Through User-Controlled Key Medium 4.3 < 1.3.7.3 1.3.7.3 2025-12-03

CVE-2025-13109

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.7.2 via the "woof_add_query" and "woof_remove_query" functions due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber level access and above, to insert or remove arbitrary saved search queries into any user's profile, including administrators.

Source: CVE.org

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.