CVE · Medium

CVE-2025-13110 — HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.7.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-13110 HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.7.4 Authorization Bypass Through User-Controlled Key Medium 4.3 < 1.3.7.4 1.3.7.4 2025-12-17

CVE-2025-13110

A security flaw exists in all versions of the HUSKY – Products Filter Professional for WooCommerce plugin up to 1.3.7.3, which can be exploited by authenticated users with a subscription or higher level access through the "woof_add_subscr" function. This vulnerability arises from inadequate verification of user-controlled input, allowing attackers to generate product messenger subscriptions under any user's name, including that of administrators.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.