PLUGIN SECURITY

Is HUSKY – Products Filter for WooCommerce Professional safe?

HUSKY - WooCommerce Products Filter Professional (former name is WOOF) – flexible, easy and robust professional filter for products for WooCommerce

What this plugin does

  • Slug: woocommerce-products-filter
  • Author: RealMag777
  • 80000+ active installs
  • 92/100 rating (336 reviews on wordpress.org)
  • 2324688 all-time downloads
  • On WordPress.org since 2014-12-01

ajax filterfilterproduct filterwoocommercewoof

Maintenance status

  • Latest known version: 1.4.3
  • Last updated: 2026-08-10 12:28pm GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 7.4+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

25 known CVEs on file for HUSKY – Products Filter for WooCommerce Professional.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-15244 HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.4.1 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Unknown < 1.4.1 1.4.1 2026-07-17 ✓ fixed in latest
CVE-2020-37174 HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] <= 1.2.3 (unfixed) Medium 5.5 < 1.2.3 1.2.3 2026-05-13 ✓ fixed in latest
CVE-2025-13110 HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.7.4 Authorization Bypass Through User-Controlled Key Medium 4.3 < 1.3.7.4 1.3.7.4 2025-12-17 ✓ fixed in latest
CVE-2025-13109 HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.7.3 Authorization Bypass Through User-Controlled Key Medium 4.3 < 1.3.7.3 1.3.7.3 2025-12-03 ✓ fixed in latest
CVE-2025-11735 HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.7.2 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.5 < 1.3.7.2 1.3.7.2 2025-10-27 ✓ fixed in latest
CVE-2025-52708 HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.7.1 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') High 7.5 < 1.3.7.1 1.3.7.1 2025-06-19 ✓ fixed in latest
CVE-2025-26890 HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.6.5 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') High 7.5 < 1.3.6.5 1.3.6.5 2025-03-14 ✓ fixed in latest
CVE-2024-11400 HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.6.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 1.3.6.4 1.3.6.4 2024-11-19 ✓ fixed in latest
+ 20 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-7491 HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.6.2 Missing Authorization Medium 4.3 < 1.3.6.2 1.3.6.2 2024-09-24 ✓ fixed in latest
CVE-2024-43121 HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.6.2 Improper Privilege Management High 7.2 < 1.3.6.2 1.3.6.2 2024-08-07 ✓ fixed in latest
CVE-2024-6457 HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.6.1 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.5 < 1.3.6.1 1.3.6.1 2024-07-15 ✓ fixed in latest
CVE-2024-5039 HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.6 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 1.3.6 1.3.6 2024-05-28 ✓ fixed in latest
CVE-2024-32680 HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.5.3 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') High 8.8 < 1.3.5.3 1.3.5.3 2024-04-17 ✓ fixed in latest
CVE-2024-3061 HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.5.3 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') High 7.2 < 1.3.5.3 1.3.5.3 2024-03-28 ✓ fixed in latest
CVE-2024-30462 HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.5.2 Cross-Site Request Forgery (CSRF) Medium 4.3 < 1.3.5.2 1.3.5.2 2024-03-28 ✓ fixed in latest
CVE-2024-1796 HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.5.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.3.5.2 1.3.5.2 2024-03-14 ✓ fixed in latest
CVE-2024-1795 HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.5.3 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 8.8 < 1.3.5.3 1.3.5.3 2024-03-14 ✓ fixed in latest
CVE-2023-50861 HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.4.4 Cross-Site Request Forgery (CSRF) Medium 4.3 < 1.3.4.4 1.3.4.4 2023-12-22 ✓ fixed in latest
CVE-2023-40010 HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.4.3 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Critical 9.3 < 1.3.4.3 1.3.4.3 2023-11-27 ✓ fixed in latest
CVE-2023-40334 HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.4.3 Missing Authorization Medium 4.3 < 1.3.4.3 1.3.4.3 2023-11-23 ✓ fixed in latest
CVE-2022-4489 HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.2 Deserialization of Untrusted Data High 7.2 < 1.3.2 1.3.2 2023-01-11 ✓ fixed in latest
CVE-2021-25085 HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.2.6.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 1.2.6.3 1.2.6.3 2021-12-28 ✓ fixed in latest
CVE-2018-8710 HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.2.0 Improper Authentication Critical 9.8 < 1.2.0 1.2.0 2018-03-06 ✓ fixed in latest
CVE-2018-8711, CVE-2018-8710 HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 2.2.0 Improper Input Validation Critical 9.8 < 2.2.0 2.2.0 2018-03-06 ⚠ update needed
HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.1.5 Unknown < 1.1.5 1.1.5 2017-07-08 ✓ fixed in latest
HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.1.5 Unknown < 1.1.5 1.1.5 2017-07-08 ✓ fixed in latest
HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.6.6 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Critical 9.8 < 1.3.6.6 1.3.6.6 0000-00-00 ✓ fixed in latest
CVE-2025-1661 HUSKY < 1.3.6.6 - Unauthenticated Local File Inclusion Unknown < 1.3.6.6 1.3.6.6 ✓ fixed in latest

How to fix it

Keep HUSKY – Products Filter for WooCommerce Professional updated — 1.4.3 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.