Sceawere
Vulnerability Detail
CVE-2026-95608UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
HUSKY Reflected XSS Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 3h ago
- Vendor
- PluginUs.Net
- Product
- HUSKY
- Attack Type
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginUs.Net HUSKY woocommerce-products-filter allows Reflected XSS.This issue affects HUSKY: from n/a through 1.4.3.2.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-09T10:16:43.053Z",
"pubdate": "2026-10-09T10:16:43.053Z",
"executiveSummary": "A Reflected Cross-Site Scripting (XSS) vulnerability exists within the HUSKY (formerly WOOF) WooCommerce Products Filter plugin, identified by the CWE-79 classification: Improper Neutralization of Input During Web Page Generation.\nThe vulnerability affects HUSKY versions from n/a through 1.4.3.2.\nThe flaw stems from insufficient sanitization of user-supplied data before it is reflected in the web page response.\nSuccessful exploitation allows an unauthenticated remote attacker to inject and execute arbitrary JavaScript code in the context of the victim's browser session.\nThis can lead to session hijacking, unauthorized actions performed on behalf of the user, redirection to malicious domains, or the exfiltration of sensitive information, such as cookies or authentication tokens.\nExploitation generally requires a user with an active session to interact with a crafted URL provided by the attacker, making this a client-side attack vector.\nThe risk implication is significant for e-commerce platforms using the plugin, as it could compromise both administrator and customer accounts.",
"technicalDetails": "The vulnerability is a classic Reflected Cross-Site Scripting (XSS) issue within the PluginUs.Net HUSKY WooCommerce Products Filter plugin. The root cause is the plugin's failure to properly sanitize or encode user-supplied input parameters before rendering them back into the HTML output generated by the application.\nWhen a user interacts with the plugin, specifically via filter-related parameters, the application processes these inputs and reflects them within the DOM without implementing sufficient output encoding or validation. If an attacker crafts a malicious URL containing a JavaScript payload within these vulnerable parameters, they can induce the victim's browser to execute the script upon loading the page.\nThe attack flow proceeds as follows: First, the attacker identifies the vulnerable parameter used by the HUSKY plugin to handle search or filter queries. Second, the attacker constructs a URL that embeds a malicious script, often encoded to bypass basic filters. Third, the attacker distributes this link to authenticated users, such as store administrators or regular customers, through social engineering, phishing, or by embedding it in external sites.\nWhen an authenticated user clicks the link, the HUSKY plugin processes the malicious input and reflects it directly into the web page's source code. The victim's browser, receiving the injected script from a trusted origin, executes the code within the context of the vulnerable site. Because the site is trusted, the script gains access to the Document Object Model (DOM), browser storage, and cookies associated with that domain.\nThe impact of such an exploit is severe. Since the script executes within the victim's session, an attacker can steal session cookies to bypass authentication, perform unauthorized administrative actions, modify the page content to conduct further phishing, or silently capture sensitive data entered into forms. The vulnerability affects HUSKY versions up to and including 1.4.3.2 and does not require pre-existing privileges for the attacker, although it requires the victim to be authenticated to maximize the potential for session hijacking.\nThe lack of appropriate context-aware output encoding—such as using WordPress-provided functions like esc_html(), esc_attr(), or json_encode()—within the plugin's front-end rendering logic constitutes the primary technical failure."
}