CVE-2026-78172: Themify – WooCommerce Product Filter <= 1.5.5 - Reflected Cross-Site Scripting
The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via Query Parameter Name in all versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue, and what interaction is required?
An unauthenticated attacker can attempt exploitation remotely without credentials. They must persuade a user to perform an action such as clicking a crafted link for injected script to execute.
Which installations are affected?
All versions of Themify – WooCommerce Product Filter up to and including 1.5.5 are affected. The provided data does not identify a fixed version.
What is the likely impact if exploitation succeeds?
Because the injected script executes in a user's browser, an attacker may access or alter information available in that user's web session. The supplied vector rates confidentiality and integrity impact as low, with no availability impact.