S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-25085 Scanner

CVE-2021-25085 scanner - Cross-Site Scripting (XSS) vulnerability in WOOF plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.4k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-25085
6.1
CVSS

The WOOF WordPress plugin before 1.2.6.3 does not sanitise and escape the woof_redraw_elements before outputing back in an admin page, leading to a Reflected Cross-Site Scripting

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
WOOF – Products Filter for WooCommerce
AFFECTED< 1.2.6.3SAFE ✓≥ 1.2.6.3
Updated Aug 21, 2026View on NVD →
Detail

The WOOF plugin for WordPress provides its users with an efficient solution for creating and managing product filters on their website. It allows online store owners to filter products according to their specific features and attributes, assisting customers in finding the product they need and improving the overall user experience. With a user-friendly interface and various options for customization, WOOF has become a popular plugin amongst WordPress users.

However, a vulnerability designated as CVE-2021-25085 was detected in the plugin's version prior to 1.2.6.3. This vulnerability occurs due to the absence of sanitization and escaping of the woof_redraw_elements, which leads to a Reflected Cross-Site Scripting (XSS) issue. This vulnerability allows cybercriminals to inject malicious code into a website and execute it when a user visits the compromised page.

If this vulnerability is exploited, it can have devastating consequences for both website owners and their customers. Cybercriminals can use this vulnerability to gain unauthorized access to sensitive information, such as login credentials and payment details. Additionally, attackers can potentially take control of the website entirely, creating a serious threat to both the business's reputation and financial security.

Thanks to the pro features of the s4e.io platform, readers can quickly and efficiently learn about potential vulnerabilities in their digital assets. This platform provides users with automated scans and reports, identifying and prioritizing potential vulnerabilities, including XSS attacks. By utilizing this tool, website owners can stay ahead of cybercriminals and safeguard their online business.

 

REFERENCES

Solution Advice

Fortunately, there are steps that can be taken to protect against this vulnerability. The following bullet points outline some of the precautions that website owners can take to protect their digital assets:

  • Install the latest version of WOOF, which includes a fix for CVE-2021-25085.
  • Regularly update all WordPress plugins and themes to ensure that known vulnerabilities are addressed.
  • Use a web application firewall (WAF) to monitor incoming traffic and block malicious requests.
  • Implement Content Security Policy (CSP) to prevent XSS attacks.
  • Regularly scan your website for vulnerabilities using a reputable security solution.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.