PLUGIN SECURITY

Is Themify Wc Product Filter safe?

This plugin helps shoppers quickly find products in your WooCommerce shop by filtering through price, categories, attributes, tags, and more.

What this plugin does

  • Slug: themify-wc-product-filter
  • Author: themifyme
  • 20000+ active installs
  • 70/100 rating (72 reviews on wordpress.org)
  • 806327 all-time downloads
  • On WordPress.org since 2016-11-04

product filterproduct searchproduct sortwoocommerce product filterwoocommerce product search

Maintenance status

  • Latest known version: 1.5.5
  • Last updated: 2026-05-11 9:44pm GMT
  • Tested up to WordPress: 6.9.7
  • Requires PHP: 7.2+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

6 known CVEs on file for Themify Wc Product Filter. Reported between 2022 and 2024.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-44046 Themify – WooCommerce Product Filter [themify-wc-product-filter] < 1.5.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.9 < 1.5.2 1.5.2 2024-09-23 ✓ fixed in latest
CVE-2024-6027 Themify – WooCommerce Product Filter [themify-wc-product-filter] < 1.5.0 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.5 < 1.5.0 1.5.0 2024-06-20 ✓ fixed in latest
CVE-2024-2262 Themify – WooCommerce Product Filter [themify-wc-product-filter] < 1.4.4 Cross-Site Request Forgery (CSRF) Medium 4.7 < 1.4.4 1.4.4 2024-03-11 ✓ fixed in latest
CVE-2024-2263 Themify – WooCommerce Product Filter [themify-wc-product-filter] < 1.4.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 1.4.4 1.4.4 2024-03-11 ✓ fixed in latest
CVE-2024-2278 Themify – WooCommerce Product Filter [themify-wc-product-filter] < 1.4.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 1.4.4 1.4.4 2024-03-11 ✓ fixed in latest
CVE-2022-1532 Themify – WooCommerce Product Filter [themify-wc-product-filter] < 1.3.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 1.3.8 1.3.8 2022-05-18 ✓ fixed in latest

How to fix it

Keep Themify Wc Product Filter updated — 1.5.5 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.