
Product List / Grid View for Woocommerce Security & Risk Analysis
wordpress.org/plugins/gm-woo-product-list-widgetWooCommerce Products List / Grid View allows you to display a Fileter selection of products. woocommerce Product display shortcode uses the same styli …
Is Product List / Grid View for Woocommerce Safe to Use in 2026?
Mostly Safe
Score 79/100Product List / Grid View for Woocommerce is generally safe to use. 1 past CVE were resolved. Keep it updated.
The "gm-woo-product-list-widget" plugin v1.0 exhibits a mixed security posture. While it demonstrates good practices in handling SQL queries with prepared statements and avoids dangerous functions, file operations, and external HTTP requests, significant concerns remain regarding its attack surface and historical vulnerabilities. The presence of two unprotected AJAX handlers represents a direct entry point for potential attacks, as any user, regardless of authentication or authorization, could trigger these actions. The lack of nonce checks on these AJAX handlers exacerbates this risk, making them susceptible to Cross-Site Request Forgery (CSRF) attacks.
The plugin's vulnerability history, specifically a medium severity Cross-site Scripting (XSS) vulnerability reported in December 2022 which remains unpatched, is a critical red flag. This indicates a pattern of potential input sanitization or output escaping deficiencies. Coupled with the fact that only 64% of outputs are properly escaped, this reinforces the possibility of XSS vulnerabilities being present or reintroduced. The absence of taint analysis data is noted, but the existing code signals and historical data are sufficient to raise concerns.
In conclusion, while the plugin has some security strengths, the unprotected AJAX endpoints and the unpatched XSS vulnerability represent substantial risks that significantly outweigh these positives. The limited capability checks and low percentage of properly escaped outputs further contribute to an elevated risk profile. Users should exercise extreme caution and ideally seek a more thoroughly secured alternative or ensure the vendor addresses the identified vulnerabilities promptly.
Key Concerns
- Unprotected AJAX handlers
- Missing nonce checks on AJAX
- Output escaping insufficient
- Unpatched CVE (medium severity XSS)
- Limited capability checks
Product List / Grid View for Woocommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Product list Widget for Woocommerce <= 1.0 - Reflected Cross-Site Scripting
Product List / Grid View for Woocommerce Code Analysis
Output Escaping
Product List / Grid View for Woocommerce Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
Product List / Grid View for Woocommerce Maintenance & Trust
Maintenance Signals
Community Trust
Product List / Grid View for Woocommerce Alternatives
Product List / Grid View for Woocommerce Developer Profile
26 plugins · 12K total installs
How We Detect Product List / Grid View for Woocommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gm-woo-product-list-widget/css/style.css/wp-content/plugins/gm-woo-product-list-widget/css/style.css?ver=HTML / DOM Fingerprints
gmwplw_settingschangecatshowc_taxonomy_valgmwplw_select_typegmwplw_product_showgmwplw_show_per_columngmwplw_thumgmwplw_order_bygmwplw_order+2 more[gmwplw_product_layout