
HUSKY – Products Filter Professional for WooCommerce Security & Risk Analysis
wordpress.org/plugins/woocommerce-products-filterHUSKY - WooCommerce Products Filter Professional (former name is WOOF) – flexible, easy and robust professional filter for products for WooCommerce
Is HUSKY – Products Filter Professional for WooCommerce Safe to Use in 2026?
Mostly Safe
Score 76/100HUSKY – Products Filter Professional for WooCommerce is generally safe to use. 23 past CVEs were resolved.
The "woocommerce-products-filter" plugin version 1.3.8.1 presents a mixed security posture. While it demonstrates some good security practices such as a high percentage of prepared SQL statements and properly escaped output, significant concerns remain. The presence of 26 unprotected AJAX handlers represents a considerable attack surface, increasing the risk of unauthorized actions or data breaches. The use of the `create_function` is a known security risk, potentially leading to code injection vulnerabilities if not handled with extreme care.
The plugin's vulnerability history is deeply concerning. With a total of 23 known CVEs, including a substantial number of critical and high-severity vulnerabilities across various types like SQL Injection, Path Traversal, and Authorization Bypass, this indicates a recurring pattern of exploitable weaknesses. The fact that the last vulnerability was recorded very recently (2025-12-17) further emphasizes the ongoing nature of these security issues. Despite no currently unpatched CVEs, the historical prevalence suggests a systemic weakness that users should be highly wary of.
In conclusion, while the code analysis shows some positive indicators, the plugin's extensive history of severe vulnerabilities and the presence of unprotected entry points strongly suggest a high-risk profile. Users of this plugin should exercise extreme caution, ensure immediate updates when new versions are released, and consider alternative plugins if possible until a sustained period of security improvements is demonstrated.
Key Concerns
- Significant number of unprotected AJAX handlers
- Use of dangerous 'create_function' function
- History of 23 known CVEs (6 critical, 7 high)
- Recent critical/high vulnerabilities indicate ongoing risks
- Flows with unsanitized paths in taint analysis
HUSKY – Products Filter Professional for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
23 total CVEs
HUSKY – Products Filter Professional for WooCommerce <= 1.3.7.3 - Authenticated (Subscriber+) Insecure Direct Object Reference via 'woof_add_subscr'
HUSKY – Products Filter Professional for WooCommerce <= 1.3.7.2 - Authenticated (Subscriber+) Insecure Direct Object Reference via 'woof_add_query/woof_remove_query'
HUSKY – Products Filter Professional for WooCommerce <= 1.3.7.1 - Unauthenticated SQL Injection via `phrase` Parameter
HUSKY <= 1.3.7 - Authenticated (Contributor+) Local File Inclusion
HUSKY – Products Filter Professional for WooCommerce <= 1.3.6.4 - Unauthenticated Local File Inclusion
HUSKY – Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion
HUSKY – Products Filter for WooCommerce <= 1.3.6.3 - Reflected Cross-Site Scripting via really_curr_tax Parameter
HUSKY – Products Filter Professional for WooCommerce <= 1.3.6.1 - Insecure Direct Object Reference to Unsubscribe
HUSKY <= 1.3.6.1 - Authenticated (Shop Manager+) Arbitrary Options Update
HUSKY - Products Filter Professional for WooCommerce <= 1.3.6 - Unauthenticated Time-Based SQL Injection
HUSKY – Products Filter Professional for WooCommerce <= 1.3.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
HUSKY – Products Filter for WooCommerce (formerly WOOF) <= 1.3.5.2 - Authenticated (Subscriber+) Remote Code Execution
HUSKY – Products Filter Professional for WooCommerce <= 1.3.5.2 - Authenticated (Admin+) Local File Inclusion
HUSKY – Products Filter for WooCommerce (formerly WOOF) <= 1.3.5.1 - Cross-Site Request Forgery
HUSKY – Products Filter for WooCommerce Professional <= 1.3.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
HUSKY – Products Filter for WooCommerce Professional <= 1.3.5.2 - Authenticated (Contributor+) SQL Injection
HUSKY – Products Filter for WooCommerce (formerly WOOF) <= 1.3.4.3 - Cross-Site Request Forgery
HUSKY – Products Filter for WooCommerce (formerly WOOF) <= 1.3.4.2 - Unauthenticated SQL Injection via search terms
HUSKY – Products Filter for WooCommerce (formerly WOOF) <= 1.3.4.2 - Missing Authorization via woof_meta_get_keys()
HUSKY – Products Filter for WooCommerce Professional <= 1.3.1 - Authenticated (Admin+) PHP Object Injection
WOOF - Products Filter for WooCommerce <= 1.2.6.2 - Reflected Cross-Site Scripting
WOOF - Products Filter for WooCommerce <= 1.1.9 - Local File Inclusion
WOOF - Products Filter for WooCommerce <= 1.1.9 - Remote Code Execution
HUSKY – Products Filter Professional for WooCommerce Release Timeline
HUSKY – Products Filter Professional for WooCommerce Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
HUSKY – Products Filter Professional for WooCommerce Attack Surface
AJAX Handlers 88
Shortcodes 18
WordPress Hooks 191
Scheduled Events 1
Maintenance & Trust
HUSKY – Products Filter Professional for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
HUSKY – Products Filter Professional for WooCommerce Alternatives
Filter Everything — WordPress & WooCommerce Filters
filter-everything
The most flexible filters plugin for WordPress & WooCommerce – filter anything.
annasta Filters for WooCommerce
annasta-woocommerce-product-filters
All-in-one products search and filtering solution for your WooCommerce shop with rich features and customization options.
Better Post & Filter Widgets for Elementor
better-post-filter-widgets-for-elementor
The only free pro-grade Elementor filtering system for posts, taxonomies, custom fields, ACF, WooCommerce, WPML & more. Ditch paid limits!
PWF – Products Filter for WooCommerce
pwf-wc-product-filters
Filter WooCommerce products and WordPress post types. Filter by any criteria including categories, tags, taxonomies, price, and custom fields.
Super Product Filter for WooCommerce
super-product-filter
Enhance your shopping experience by using a product filter that streamlines the selection process, ensuring you find the perfect product effortlessly.
HUSKY – Products Filter Professional for WooCommerce Developer Profile
12 plugins · 188K total installs
How We Detect HUSKY – Products Filter Professional for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.