cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches foradditional-order-filters-for-woocommerce additional-order-filters-for-woocommerce

Direction: ascending
Jun 06, 2024

Additional Order Filters for WooCommerce # CVE-2023-47690

CVE, Research URL

CVE-2023-47690

Date
Nov 14, 2023
Research Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Anton Bond Additional Order Filters for WooCommerce plugin <= 1.10 versions.
Affected versions
Min -, max -.
Status
vulnerable
Nov 27, 2024

Additional Order Filters for WooCommerce # CVE-2024-11418

CVE, Research URL

CVE-2024-11418

Date
Nov 26, 2024
Research Description
The Additional Order Filters for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shipping_method_filter' parameter in all versions up to, and including, 1.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
Min -, max -.
Status
vulnerable
Jul 04, 2025

Additional Order Filters for WooCommerce # CVE-2025-53271

CVE, Research URL

CVE-2025-53271

Date
Jun 27, 2025
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in Anton Bond Additional Order Filters for WooCommerce allows Stored XSS. This issue affects Additional Order Filters for WooCommerce: from n/a through 1.22.
Affected versions
Min -, max -.
Status
vulnerable