CVE-2026-78172
Received Received - Intake

Reflected Cross-Site Scripting in Themify WooCommerce Product Filter Plugin

Vulnerability report for CVE-2026-78172, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: Wordfence

Description

The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via Query Parameter Name in all versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-09-11
AI Q&A
2026-09-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
themify woocommerce_product_filter to 1.5.5 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Themify – WooCommerce Product Filter plugin for WordPress has a reflected Cross-Site Scripting (XSS) vulnerability due to insufficient input sanitization and output escaping. This allows unauthenticated attackers to inject malicious scripts via query parameters. If a user clicks a crafted link, the injected script executes in their browser.

Detection Guidance

This vulnerability is specific to the Themify – WooCommerce Product Filter WordPress plugin. To detect it, inspect your WordPress site for the plugin version. If you are running version 1.5.5 or lower, the site is vulnerable. Check for unusual script execution or unexpected user interactions via reflected XSS attempts in query parameters.

Impact Analysis

An attacker could trick you into clicking a malicious link, leading to unauthorized script execution in your browser. This may result in stolen session cookies, account takeovers, or defacement of web pages you visit. No authentication is required for exploitation.

Compliance Impact

This vulnerability could lead to unauthorized access to user data, violating GDPR's data protection principles or HIPAA's security requirements. Organizations may face fines or penalties if exploited, as it compromises data confidentiality and integrity.

Mitigation Strategies

Immediately update the Themify – WooCommerce Product Filter plugin to the latest version if available. If no update exists, consider disabling or removing the plugin until a patch is released. Implement web application firewalls to filter malicious scripts and monitor for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78172. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart