Vulnerabilities and security researches foradditional-order-filters-for-woocommerce additional-order-filters-for-woocommerce
Direction: descendingJul 04, 2025
Additional Order Filters for WooCommerce # CVE-2025-53271
- CVE, Research URL
- Application
- Date
- Jun 27, 2025
- Research Description
- Cross-Site Request Forgery (CSRF) vulnerability in Anton Bond Additional Order Filters for WooCommerce allows Stored XSS. This issue affects Additional Order Filters for WooCommerce: from n/a through 1.22.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Nov 27, 2024
Additional Order Filters for WooCommerce # CVE-2024-11418
- CVE, Research URL
- Application
- Date
- Nov 26, 2024
- Research Description
- The Additional Order Filters for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shipping_method_filter' parameter in all versions up to, and including, 1.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Jun 06, 2024
Additional Order Filters for WooCommerce # CVE-2023-47690
- CVE, Research URL
- Application
- Date
- Nov 14, 2023
- Research Description
- Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Anton Bond Additional Order Filters for WooCommerce plugin <= 1.10 versions.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable