PLUGIN SECURITY
Is HUSKY – Products Filter for WooCommerce Professional safe?
HUSKY - WooCommerce Products Filter Professional (former name is WOOF) – flexible, easy and robust professional filter for products for WooCommerce
What this plugin does
- Slug:
woocommerce-products-filter - Author: RealMag777
- 80000+ active installs
- 92/100 rating (336 reviews on wordpress.org)
- 2324688 all-time downloads
- On WordPress.org since 2014-12-01
ajax filterfilterproduct filterwoocommercewoof
Maintenance status
- Latest known version: 1.4.3
- Last updated: 2026-08-10 12:28pm GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 7.4+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
25 known CVEs on file for HUSKY – Products Filter for WooCommerce Professional.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-15244 | HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.4.1 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Unknown | < 1.4.1 | 1.4.1 | 2026-07-17 | ✓ fixed in latest |
| CVE-2020-37174 | HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] <= 1.2.3 (unfixed) | — | Medium 5.5 | < 1.2.3 | 1.2.3 | 2026-05-13 | ✓ fixed in latest |
| CVE-2025-13110 | HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.7.4 | Authorization Bypass Through User-Controlled Key | Medium 4.3 | < 1.3.7.4 | 1.3.7.4 | 2025-12-17 | ✓ fixed in latest |
| CVE-2025-13109 | HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.7.3 | Authorization Bypass Through User-Controlled Key | Medium 4.3 | < 1.3.7.3 | 1.3.7.3 | 2025-12-03 | ✓ fixed in latest |
| CVE-2025-11735 | HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.7.2 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 7.5 | < 1.3.7.2 | 1.3.7.2 | 2025-10-27 | ✓ fixed in latest |
| CVE-2025-52708 | HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.7.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') | High 7.5 | < 1.3.7.1 | 1.3.7.1 | 2025-06-19 | ✓ fixed in latest |
| CVE-2025-26890 | HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.6.5 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') | High 7.5 | < 1.3.6.5 | 1.3.6.5 | 2025-03-14 | ✓ fixed in latest |
| CVE-2024-11400 | HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.6.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 1.3.6.4 | 1.3.6.4 | 2024-11-19 | ✓ fixed in latest |
+ 20 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2024-7491 | HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.6.2 | Missing Authorization | Medium 4.3 | < 1.3.6.2 | 1.3.6.2 | 2024-09-24 | ✓ fixed in latest |
| CVE-2024-43121 | HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.6.2 | Improper Privilege Management | High 7.2 | < 1.3.6.2 | 1.3.6.2 | 2024-08-07 | ✓ fixed in latest |
| CVE-2024-6457 | HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.6.1 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 7.5 | < 1.3.6.1 | 1.3.6.1 | 2024-07-15 | ✓ fixed in latest |
| CVE-2024-5039 | HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.6 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 1.3.6 | 1.3.6 | 2024-05-28 | ✓ fixed in latest |
| CVE-2024-32680 | HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.5.3 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | High 8.8 | < 1.3.5.3 | 1.3.5.3 | 2024-04-17 | ✓ fixed in latest |
| CVE-2024-3061 | HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.5.3 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') | High 7.2 | < 1.3.5.3 | 1.3.5.3 | 2024-03-28 | ✓ fixed in latest |
| CVE-2024-30462 | HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.5.2 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 1.3.5.2 | 1.3.5.2 | 2024-03-28 | ✓ fixed in latest |
| CVE-2024-1796 | HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.5.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 1.3.5.2 | 1.3.5.2 | 2024-03-14 | ✓ fixed in latest |
| CVE-2024-1795 | HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.5.3 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 8.8 | < 1.3.5.3 | 1.3.5.3 | 2024-03-14 | ✓ fixed in latest |
| CVE-2023-50861 | HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.4.4 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 1.3.4.4 | 1.3.4.4 | 2023-12-22 | ✓ fixed in latest |
| CVE-2023-40010 | HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.4.3 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Critical 9.3 | < 1.3.4.3 | 1.3.4.3 | 2023-11-27 | ✓ fixed in latest |
| CVE-2023-40334 | HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.4.3 | Missing Authorization | Medium 4.3 | < 1.3.4.3 | 1.3.4.3 | 2023-11-23 | ✓ fixed in latest |
| CVE-2022-4489 | HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.2 | Deserialization of Untrusted Data | High 7.2 | < 1.3.2 | 1.3.2 | 2023-01-11 | ✓ fixed in latest |
| CVE-2021-25085 | HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.2.6.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 1.2.6.3 | 1.2.6.3 | 2021-12-28 | ✓ fixed in latest |
| CVE-2018-8710 | HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.2.0 | Improper Authentication | Critical 9.8 | < 1.2.0 | 1.2.0 | 2018-03-06 | ✓ fixed in latest |
| CVE-2018-8711, CVE-2018-8710 | HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 2.2.0 | Improper Input Validation | Critical 9.8 | < 2.2.0 | 2.2.0 | 2018-03-06 | ⚠ update needed |
| — | HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.1.5 | — | Unknown | < 1.1.5 | 1.1.5 | 2017-07-08 | ✓ fixed in latest |
| — | HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.1.5 | — | Unknown | < 1.1.5 | 1.1.5 | 2017-07-08 | ✓ fixed in latest |
| — | HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.6.6 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Critical 9.8 | < 1.3.6.6 | 1.3.6.6 | 0000-00-00 | ✓ fixed in latest |
| CVE-2025-1661 | HUSKY < 1.3.6.6 - Unauthenticated Local File Inclusion | — | Unknown | < 1.3.6.6 | 1.3.6.6 | — | ✓ fixed in latest |
How to fix it
Keep HUSKY – Products Filter for WooCommerce Professional updated — 1.4.3 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Filter Everything — WordPress & WooCommerce Filters — 50000+ active installs — 90/100 (148) — max PHP 8.4
- Search & Filter — 50000+ active installs — 90/100 (175) — max PHP 8.4
- Allow HTML in Category Descriptions — 8000+ active installs — 100/100 (41) — max PHP 8.4
- Category AJAX Filter – Posts, Custom Post Types & Product Filter — 6000+ active installs — 98/100 (153)
- Jetpack Search — 5000+ active installs — 90/100 (10)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.