WordPress HUSKY β Products Filter for WooCommerce (formerly WOOF) Plugin <= 1.3.4.2 is vulnerable to SQL Injection
CVE-2023-40010
9.3CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 December 2023
What is CVE-2023-40010?
The HUSKY β Products Filter for WooCommerce Professional plugin has a vulnerability that allows for improper neutralization of special elements in SQL commands, leading to potential SQL Injection attacks. This issue poses a security risk for users running the plugin from unspecified versions through 1.3.4.2, as an attacker could exploit this flaw to execute arbitrary SQL code, gain unauthorized access to sensitive data, and compromise site security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
HUSKY β Products Filter for WooCommerce Professional <= 1.3.4.2
References
CVSS V3.1
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Tien Nguyen Anh (Patchstack Alliance)