CVE-2022-1532: Themify Woocommerce Product Filter
Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.
Themify WordPress plugin before 1.3.8 does not sanitise and escape the page parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
Affected products
- Themify Woocommerce Product Filter: before 1.3.8 (fixed in 1.3.8)
Published 2022-06-13. Last modified 2026-06-17.