CVE-2026-87869
Received Received - Intake

Reflected Cross-Site Scripting in Filter Everything WordPress Plugin

Vulnerability report for CVE-2026-87869, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: Wordfence

Description

The Filter Everything β€” WordPress & WooCommerce Filters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.9.6. This is due to insufficient input sanitization and output escaping in the flrt_elementor_load_more_anchor() function. The function reads query parameters from $_SERVER['REQUEST_URI'] via getFormActionOrFullPageUrl(true), which URL-decodes them through parse_str() and re-assembles them using build_query() β€” a WordPress core function that does NOT re-encode values ($urlencode=false). The resulting URL, containing unescaped special characters, is injected into a data-next-page HTML attribute via preg_replace() without esc_attr() or esc_url(). This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
stepasyuk Filter EverythingΒ β€” WordPress & WooCommerce Filters 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Reflected Cross-Site Scripting (XSS) vulnerability in the Filter Everything plugin for WordPress and WooCommerce. It affects versions up to 1.9.6 due to improper input sanitization and output escaping in the flrt_elementor_load_more_anchor() function. The flaw allows attackers to inject malicious scripts via specially crafted URLs that are not properly encoded, potentially executing when a user clicks the link.

Detection Guidance

This vulnerability can be detected by checking if the Filter Everything plugin version 1.9.6 or below is installed on your WordPress site. Inspect the plugin files for the vulnerable flrt_elementor_load_more_anchor() function and review the code for improper sanitization and escaping in the data-next-page HTML attribute.

Impact Analysis

An attacker could trick you into clicking a malicious link, which may execute arbitrary scripts in your browser. This could lead to session hijacking, stealing cookies, or redirecting you to phishing sites. Since it requires user interaction, the risk depends on whether you click untrusted links.

Compliance Impact

This XSS vulnerability could compromise user data privacy, potentially violating GDPR (data protection) or HIPAA (health data security) if exploited. Organizations using the vulnerable plugin may face compliance risks due to unauthorized script execution accessing sensitive information.

Mitigation Strategies

Immediately update the Filter Everything plugin to the latest version if available. If no update is available, consider disabling or removing the plugin until a patch is released. Additionally, implement strict input validation and output escaping in your WordPress environment to prevent similar issues.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87869. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart