Skip to main content
QUIETLYTIC
Vulnerability

HUSKY – Products Filter Professional for WooCommerce Vulnerability (CVE-2026-18562)

CVE-2026-18562 is a CVSS 6.1 reflected XSS in the HUSKY Products Filter plugin for WooCommerce, per VulnCheck alone.

CVE-2026-18562
Threat Level
MEDIUM
CVSS
6.1
Status
Active Exploitation
Confidence
Medium
Affected Products
HUSKY – Products Filter Professional for WooCommerce (up to 1.4.3)

CVE-2026-18562 carries a CVSS 3.1 base score of 6.1 against HUSKY – Products Filter Professional for WooCommerce, a WordPress plugin, affecting versions up to and including 1.4.3. NVD classifies it as CWE-79 (Cross-Site Scripting). VulnCheck’s KEV feed reports the CVE as exploited, dated September 14, 2026.

That exploitation report is single-sourced. CISA has not added CVE-2026-18562 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion. No Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.

What the flaw is

Per NVD, the plugin’s SEO-friendly permalink structure lets filter values travel as URL path segments rather than query-string parameters. When the plugin parses those path segments back into filter values and embeds them into an inline JavaScript block on the page, it does so with insufficient escaping. We are deliberately not reproducing NVD’s own more specific description of exactly which internal function and encoding step allows the escaping gap to succeed; verified absent from this article. The practical result NVD describes is that an unauthenticated attacker can craft a link that, when a victim clicks it, executes arbitrary script in the victim’s browser in the context of the site.

Evidence and confidence

  • Medium confidence — the CVSS 6.1 score, the vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N), the CWE-79 classification, and the described mechanism all trace to NVD alone in our current ingestion, corroborated by a Wordfence Threat Intelligence advisory cited in NVD’s own reference list. The exploitation report traces to VulnCheck KEV alone.
  • Low-to-moderate exploitation probability — FIRST’s EPSS model scores this CVE at 0.00227, a 13.6th percentile score as of our ingestion.

No field is in conflict between our two sources. Our source data does not carry a specific fixed-version number.

Why this matters

Reflected XSS requiring user interaction (UI:R — a victim has to click a crafted link) is a lower-severity class than stored or unauthenticated persistent XSS, but it remains a viable phishing-chain component: an attacker can pair a crafted link with a convincing pretext to compromise site visitors or administrators who click it, and the CVSS vector’s Changed scope (S:C) reflects that the resulting script can affect the security context of the broader site, not just the requesting browser session. Sites running this plugin up to 1.4.3 should treat this as a priority patch, particularly given confirmed exploitation.

Frequently Asked Questions

What is CVE-2026-18562? A CVSS 6.1 reflected cross-site scripting vulnerability (CWE-79) in the HUSKY – Products Filter Professional for WooCommerce WordPress plugin, affecting versions up to and including 1.4.3, reachable via crafted SEO-friendly filter URL path segments.

Is CVE-2026-18562 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated September 14, 2026. That report is single-sourced; CISA has not listed this CVE in its own Known Exploited Vulnerabilities catalog as of our current ingestion, and we have no independent corroboration.

Do I need an account to exploit this? No. NVD’s description confirms this is exploitable by an unauthenticated attacker, though it requires a victim to click a crafted link (UI:R).

Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.

Is a fixed version available? Our source data does not carry a specific fixed-version number beyond NVD’s statement that versions up to and including 1.4.3 are affected. Consult the plugin vendor directly for the current patched release.


Severity, vector, and weakness classification sourced from the National Vulnerability Database record for CVE-2026-18562, corroborated by Wordfence’s Threat Intelligence advisory. Exploitation status and the September 14, 2026 catalog date reported by VulnCheck KEV. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our current ingestion. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 VulnCheck KEV

Related intelligence


Analyst tools