S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Mar 13, 2025

CVE-2025-1661 Scanner

CVE-2025-1661 Scanner - Local File Inclusion (LFI) vulnerability in HUSKY – Products Filter Professional for WooCommerce

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.8k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-1661
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.6.5 via the 'template' parameter of the woof_text_search AJAX action. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
HUSKY – Products Filter Professional for WooCommerceby realmag777
0
Updated Sep 9, 2026View on NVD →
Detail

The HUSKY – Products Filter Professional for WooCommerce is a powerful plugin used in WordPress to enhance the e-commerce capability of WooCommerce stores. It is designed to help store owners and developers create advanced product filtering options for users, improving the shopping experience by narrowing down product searches efficiently. This plugin is widely used in online retail and e-commerce environments across various industries. By allowing customers to sort through products with ease, it aims to increase engagement and conversion rates. Its functionalities are tailored for shop managers, developers, and site owners looking to enhance the product discovery process on their sites. However, without keeping it up-to-date, users may risk the presence of vulnerabilities that can compromise store security.

The Local File Inclusion (LFI) vulnerability detected in this plugin occurs when a malicious actor is able to include files on a server through the web browser. This vulnerability can lead to code execution, leakage of sensitive data, and full server compromise if improperly handled. In this specific case, the vulnerability is triggered via the 'template' parameter in the woof_text_search AJAX action, which allows the inclusion and execution of arbitrary files. Hackers could exploit this flaw to run PHP code from included files on the server. Given the CVSS score of 9.8, this vulnerability poses a critical risk to vulnerable systems, especially where PHP files can be uploaded and executed. Protection and immediate updates are essential to prevent malicious exploitation.

Technical details reveal that the vulnerability is present due to incorrect handling of the 'template' parameter in the plugin's AJAX action. The parameter allows path traversal to include files that are not meant to be accessed, such as configuration files. Attackers can craft a payload to manipulate this parameter and load malicious scripts or local files within the server, potentially escalating their access privileges. By crafting specific requests, they can misuse the AJAX function to access sensitive configurations like wp-config.php, leading to severe outcomes. Systems running this plugin on any WooCommerce store should closely monitor path inputs and sanitize any untrusted user input comprehensively to prevent exploitation.

If exploited by malicious parties, the LFI vulnerability could allow attackers to upload and execute arbitrary PHP files from the server. This can result in data breaches where sensitive customer and business information is exposed. Attackers might manage to leverage the flaw to gain unauthorized administrative access, manipulate store operations, or execute commands that should otherwise be protected. Further negative effects include website defacement, loss of data integrity, and potential financial losses due to compromised customer trust and store functionality interruptions. Countermeasures should aim to mitigate these risks by closing the vulnerability and monitoring systems for unusual activities proactively.

REFERENCES

Solution Advice
  • Update the HUSKY – Products Filter Professional for WooCommerce plugin to version 1.3.6.6 or a newer patched version.
  • Implement strong input validation and encoding practices to prevent unauthorized file access.
  • Regularly audit and review security settings of plugins for any possible vulnerabilities.
  • Monitor server access logs for suspicious activities and unexpected file inclusion attempts.
  • Use web application firewalls (WAFs) to block malicious requests targeting file inclusion.
  • Ensure file permissions are set correctly to restrict unauthorized access and execution of sensitive files.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2025-1661 Scanner - Local File Inclusion (LFI) vulnerability in HUSKY – Products Filter Professional for WooCommerce | S4E