Vulnerability record · CVE-2025-1661 · published 11 March 2025
CVE-2025-1661: HUSKY WooCommerce Products Filter Plugin Unauthenticated Local File Inclusion
Pluginus · Husky Products Filter Professional For Woocommerce
The HUSKY – Products Filter Professional for WooCommerce WordPress plugin is vulnerable to Local File Inclusion in all versions up to and including 1.3.6.5 via the 'template' parameter of the woof_text_search AJAX action. Because the endpoint is reachable without authentication, an attacker can include and execute arbitrary server-side files, which can lead to PHP code execution. This is a critical issue for any site running the affected plugin.
Description
The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.6.5 via the 'template' parameter of the woof_text_search AJAX action. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, high EPSS, and potential for remote code execution make this an urgent patching priority.
What it is
The HUSKY – Products Filter Professional for WooCommerce WordPress plugin is vulnerable to Local File Inclusion in all versions up to and including 1.3.6.5 via the 'template' parameter of the woof_text_search AJAX action. Because the endpoint is reachable without authentication, an attacker can include and execute arbitrary server-side files, which can lead to PHP code execution. This is a critical issue for any site running the affected plugin.
Impact
An attacker can read sensitive files, bypass access controls, and execute PHP code if they can get a file with PHP content onto the server (for example via an uploaded image or other 'safe' file type). Successful exploitation can result in full site compromise.
Attack surface
The flaw is reached over the network through the woof_text_search AJAX action, specifically the 'template' parameter. No authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
The CVE is not listed in CISA KEV, but EPSS is high at 0.56382 (99th percentile), indicating a strong likelihood of exploitation activity. No public exploit references are tagged in the record beyond the patch and advisory links.
What to do
- Update the HUSKY – Products Filter Professional for WooCommerce plugin to a version newer than 1.3.6.5 immediately.
- If patching is not possible, disable or remove the plugin until an update can be applied.
- Restrict or block access to the woof_text_search AJAX endpoint at the web server or WAF level.
- Audit upload directories and file permissions to prevent inclusion of attacker-controlled files.
- Monitor for unexpected file inclusion attempts and PHP execution in upload paths.
Detection
- Search web server logs for requests to admin-ajax.php with action=woof_text_search and suspicious 'template' parameter values containing path traversal sequences or absolute paths.
- Monitor for inclusion of files from upload directories or other non-plugin paths in PHP error logs or access logs.
- Use file integrity monitoring to detect unexpected PHP files in uploads or other writable directories.
- Review WAF alerts for local file inclusion patterns targeting the woof_text_search action.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2025-1661 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-1661), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.