RULE(RULE ID:338771)

Rule General Information
Release Date: 2025-04-02
Rule Name: WordPress plugin HUSKY Products Filter Professional for WooCommerce Directory Traversal Vulnerability (CVE-2025-1661)
Severity:
CVE ID:
Rule Protection Details
Description: WordPress and WordPress plugins are products of the WordPress Foundation. WordPress is a blogging platform developed using the PHP language. This platform supports the setup of personal blog websites on servers with PHP and MySQL. A WordPress plugin is an application plugin.The WordPress plugin HUSKY Products Filter Professional for WooCommerce, versions 1.3.6.5 and earlier, has a path traversal vulnerability. This vulnerability arises because the template parameter in the woof_text_search AJAX operation allows unauthenticated attackers to include and execute arbitrary files on the server. This can bypass access controls, obtain sensitive data, or achieve code execution.
Impact: An attacker can abtain sensitive information of the target victim, and do malicious actions to gain profits using the information.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch:https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woocommerce-products-filter/husky-products-filter-professional-for-woocommerce-1365-unauthenticated-local-file-inclusion