CVE-2025-1661 Details
Description
The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.6.5 via the 'template' parameter of the woof_text_search AJAX action. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
A local file inclusion vulnerability has been identified in the HUSKY – Products Filter Professional for WooCommerce plugin, affecting all versions through 1.3.6.5. The vulnerability arises in the 'template' parameter of the woof_text_search AJAX action, allowing unauthenticated attackers to include and execute arbitrary files on the server. This exploitation could bypass access controls, access sensitive data, or execute code in cases where files of certain types, like images, can be uploaded and included.
Users are advised to update the HUSKY – Products Filter Professional for WooCommerce plugin to version 1.3.6.6 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 11, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| pluginus husky - products filter professional for woocommerce | < 1.3.6.6 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 19, 2025 | Initial Analysis | [email protected] |
| Mar 11, 2025 | New CVE Received | [email protected] |