Reflected Cross-Site Scripting in HUSKY Products Filter Professional for WooCommerce
CVE-2026-18562
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 11 September 2026
What is CVE-2026-18562?
The HUSKY Products Filter Professional plugin for WooCommerce is susceptible to a Reflected Cross-Site Scripting vulnerability due to inadequate input sanitization and output escaping in the wp_load_js() function. This flaw arises from the parsing of filter values from SEO-friendly URL segments, where ineffective escaping allows unauthenticated attackers to embed malicious scripts. If exploited, these scripts could execute in the context of users who are tricked into following crafted links, posing serious security risks.
Affected Version(s)
HUSKY β Products Filter for WooCommerce Professional 0 <= 1.4.3