Medium severity6.1NVD Advisory· Published Feb 1, 2022· Updated Jun 17, 2026
CVE-2021-25085
CVE-2021-25085
Description
The WOOF WordPress plugin before 1.2.6.3 does not sanitise and escape the woof_redraw_elements before outputing back in an admin page, leading to a Reflected Cross-Site Scripting
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:pluginus:woocommerce_products_filter:*:*:*:*:*:wordpress:*:*Range: <1.2.6.3
- WordPress/WOOFdescription
- Range: <1.2.6.3
Patches
Vulnerability mechanics
References
2- plugins.trac.wordpress.org/changeset/2648751nvdPatchThird Party Advisory
- wpscan.com/vulnerability/b7dd81c6-6af1-4976-b928-421ca69bfa90nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.