CVE-2026-87869: Filter Everything — WordPress & WooCommerce Filters <= 1.9.6 - Reflected Cross-Site Scripting via Elementor Posts Widget Pagination URL
The Filter Everything — WordPress & WooCommerce Filters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.9.6. This is due to insufficient input sanitization and output escaping in the flrtelementorloadmoreanchor() function. The function reads query parameters from $SERVER['REQUESTURI'] via getFormActionOrFullPageUrl(true), which URL-decodes them through parsestr() and re-assembles them using buildquery() — a WordPress core function that does NOT re-encode values ($urlencode=false). The resulting URL, containing unescaped special characters, is injected into a data-next-page HTML attribute via pregreplace() without escattr() or escurl(). This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link.