Filter Plus Security & Risk Analysis

wordpress.org/plugins/filter-plus

Filter Plus is a WordPress filter plugin and WooCommerce product filter. Add AJAX filtering by price, rating, attributes, and categories.

100 active installs v1.1.26 PHP 7.4+ WP + Updated Jun 26, 2026
ajax-product-filterfilter-by-priceproduct-filterwoocommerce-product-filterwordpress-filter-plugin
77
B · Generally Safe
CVEs total2
Unpatched1
Last CVEFeb 5, 2026
Safety Verdict

Is Filter Plus Safe to Use in 2026?

Mostly Safe

Score 77/100

Filter Plus is generally safe to use. 2 past CVEs were resolved.

2 known CVEs 1 unpatched Last CVE: Feb 5, 2026Updated 1mo ago
Risk Assessment

The "filter-plus" v1.1.17 plugin exhibits a generally strong security posture based on the static analysis. The absence of entry points like AJAX handlers, REST API routes, shortcodes, and cron events significantly reduces the attack surface. Furthermore, the code demonstrates good practices with 100% of SQL queries using prepared statements and a very high percentage (98%) of output properly escaped. The presence of nonce and capability checks further bolsters its defenses. However, a past medium severity vulnerability related to missing authorization, even though currently patched, is a notable concern. This historical pattern suggests a potential area where authorization checks might be overlooked during development, requiring continued vigilance. While the current version appears to be well-secured, the single historical medium vulnerability warrants a slightly cautious approach, indicating that while current practices are good, past issues have existed.

Key Concerns

  • Past medium severity vulnerability (Missing Auth)
  • Bundled library (Select2) could be outdated
Vulnerabilities
2 published

Filter Plus Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
1 CVE in 2026 · unpatched
2026
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2026-39607medium · 4.3Missing Authorization

Filter Plus <= 1.1.17 - Missing Authorization

Feb 5, 2026Unpatched
CVE-2025-13314medium · 5.3Missing Authorization

Product Filtering by Categories, Tags, Price Range for WooCommerce <= 1.1.6 - Missing Authorization to Unauthenticated Plugin Settings Modification

Dec 11, 2025 Patched in 1.1.7 (1d)
Version History

Filter Plus Release Timeline

v1.1.26Current1 CVE
v1.1.251 CVE
v1.1.241 CVE
v1.1.231 CVE
v1.1.221 CVE
v1.1.211 CVE
v1.1.201 CVE
v1.1.191 CVE
v1.1.181 CVE
v1.1.171 CVE
v1.1.161 CVE
v1.1.151 CVE
v1.1.141 CVE
v1.1.131 CVE
v1.1.121 CVE
v1.1.111 CVE
v1.1.101 CVE
v1.1.91 CVE
v1.1.81 CVE
v1.1.71 CVE
Code Analysis
Analyzed Mar 16, 2026

Filter Plus Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
19
826 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

100% prepared2 total queries

Output Escaping

98% escaped845 total outputs
Attack Surface

Filter Plus Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
actionadmin_enqueue_scriptsbase\enqueue.php:22
actionwp_enqueue_scriptsbase\enqueue.php:24
actionadmin_menucore\admin\menus.php:26
filterwoocommerce_get_price_suffixcore\compatibility\hooks.php:20
actionelementor/frontend/before_enqueue_scriptscore\core.php:44
actioninitcore\widgets\bricks\manifest.php:24
actionelementor/elements/categories_registeredcore\widgets\elementor\manifest.php:16
actionelementor/widgets/registercore\widgets\elementor\manifest.php:17
actioninitcore\widgets\gutenburg-block\blocks\woo-filter.php:176
actioninitcore\widgets\gutenburg-block\blocks\wp-filter.php:15
filterblock_categories_allcore\widgets\gutenburg-block\init.php:64
filterblock_categoriescore\widgets\gutenburg-block\init.php:66
actioninitcore\widgets\gutenburg-block\init.php:70
actionplugins_loadedfilter-plus.php:69
Maintenance & Trust

Filter Plus Maintenance & Trust

Maintenance Signals

WordPress version tested7.0.2
Last updatedJun 26, 2026
PHP min version7.4
Downloads17K

Community Trust

Rating70/100
Number of ratings4
Active installs100
Developer Profile

Filter Plus Developer Profile

Wpbens

5 plugins · 140 total installs

97
trust score
Avg Security Score
95/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Filter Plus

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/filter-plus/assets/js/filter-plus-select2.js/wp-content/plugins/filter-plus/assets/js/admin.js/wp-content/plugins/filter-plus/assets/css/admin.css/wp-content/plugins/filter-plus/assets/css/select2.css/wp-content/plugins/filter-plus/assets/js/search-filter.js/wp-content/plugins/filter-plus/assets/js/filter-option.js/wp-content/plugins/filter-plus/assets/js/filter-swiper-bundle.min.js
Script Paths
/wp-content/plugins/filter-plus/assets/js/filter-plus-select2.js/wp-content/plugins/filter-plus/assets/js/admin.js/wp-content/plugins/filter-plus/assets/js/search-filter.js/wp-content/plugins/filter-plus/assets/js/filter-option.js/wp-content/plugins/filter-plus/assets/js/filter-swiper-bundle.min.js
Version Parameters
filter-plus/style.css?ver=filter-plus/admin.css?ver=filter-plus/select2.css?ver=filter-plus/filter-plus-select2.js?ver=filter-plus/admin.js?ver=filter-plus/search-filter.js?ver=filter-plus/filter-option.js?ver=filter-plus/filter-swiper-bundle.min.js?ver=

HTML / DOM Fingerprints

JS Globals
filter_admin
FAQ

Frequently Asked Questions about Filter Plus