Sceawere

Vulnerability Detail

CVE-2026-87869UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Reflected XSS in Filter Everything

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.1
Creation Date
3h ago
Vendor
stepasyuk
Product
Filter Everything — WordPress & WooCommerce Filters
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Filter Everything — WordPress & WooCommerce Filters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.9.6. This is due to insufficient input sanitization and output escaping in the flrt_elementor_load_more_anchor() function. The function reads query parameters from $_SERVER['REQUEST_URI'] via getFormActionOrFullPageUrl(true), which URL-decodes them through parse_str() and re-assembles them using build_query() — a WordPress core function that does NOT re-encode values ($urlencode=false). The resulting URL, containing unescaped special characters, is injected into a data-next-page HTML attribute via preg_replace() without esc_attr() or esc_url(). This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.1",
  "pubDate": "2026-10-10T05:16:40.277Z",
  "pubdate": "2026-10-10T05:16:40.277Z",
  "executiveSummary": "The Filter Everything — WordPress & WooCommerce Filters plugin contains a critical Reflected Cross-Site Scripting (XSS) vulnerability affecting versions up to and including 1.9.6.\nThe vulnerability arises from improper handling of user-supplied input within the flrt_elementor_load_more_anchor() function, where query parameters are processed and reflected back into the HTML document without adequate sanitization or output encoding.\nThis flaw permits unauthenticated attackers to execute arbitrary JavaScript within the context of a victim's browser session.\nExploitation requires a user to interact with a maliciously crafted URL, potentially leading to unauthorized actions, session hijacking, or the exfiltration of sensitive information.\nThe risk is significant due to the nature of Reflected XSS, which can be leveraged for credential theft or site defacement depending on the application environment.\nUsers are strongly encouraged to update to a patched version once available and apply security best practices to mitigate the risk of exploitation.",
  "technicalDetails": "The root cause of this vulnerability is improper data flow management within the flrt_elementor_load_more_anchor() function. The function retrieves the current request URI via getFormActionOrFullPageUrl(true) and processes query parameters using parse_str().\nA critical security failure occurs during the re-assembly of these parameters using the build_query() function. Because the $urlencode argument is set to false, special characters within the query string are not properly encoded. This lack of transformation preserves malicious payloads containing HTML or JavaScript special characters.\nThese unescaped values are subsequently injected into the 'data-next-page' HTML attribute using preg_replace(). Crucially, this operation fails to utilize WordPress defensive functions such as esc_attr() or esc_url(), which are standard requirements for preventing cross-site scripting when rendering user-influenced content in HTML attributes.\nThe attack flow proceeds as follows: 1) An attacker crafts a URL containing a malicious payload within the query parameters. 2) The attacker baits an authenticated or unauthenticated user into clicking this specially crafted link. 3) The server-side code processes the URI, extracts the malicious parameters, and fails to sanitize the output, embedding the payload directly into the 'data-next-page' attribute. 4) The victim's browser parses the rendered HTML, triggering the execution of the injected script within the security context of the affected WordPress site.\nThe vulnerability is persistent in versions up to and including 1.9.6. It is exploitable remotely over the network without requiring any prior authentication or specific privilege levels. The post-exploitation impact includes the potential for full session hijacking, unauthorized modifications to the page content, or the redirection of users to malicious third-party domains.\nBecause the payload is injected into an attribute via server-side logic, the vulnerability bypasses basic client-side input validation, placing the burden of security entirely on the proper implementation of output encoding in the vulnerable function."
}
CVE-2026-87869: Reflected XSS in Filter Everything (MEDIUM Severity, CVSS: 6.1) | Sceawere