Pluginus develops WordPress plugins focused on e-commerce product management and filtering, including widely adopted tools like Bear and Husky that extend WooCommerce functionality. Its vulnerability profile concentrates on web-application input-handling and authorization weaknesses—cross-site scripting, cross-site request forgery, missing authorization, path traversal, and code injection—reflecting the challenges of server-rendered plugin code that interfaces with user input and WordPress permission models. A meaningful share of disclosures reach serious severity, and vulnerabilities in this vendor's portfolio have a moderate tendency toward public exploit availability. Defenders managing WooCommerce storefronts should prioritize this vendor's updates for store-facing plugins and monitor for post-exploitation artifacts on compromised sites. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pluginus over time
Signals from CVEs in this vendor scope (85 CVEs).
85 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-1661CRITICAL The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.6.5 via the 'template' | Mar 11, 2025 | 9.8 | 72 | NO | YES |
CVE-2022-4063CRITICAL The InPost Gallery WordPress plugin before 2.1.4.1 insecurely uses PHP's extract() function when rendering HTML views, allowing attackers to force the inclusion of malicious files | Dec 19, 2022 | 9.8 | 47 | NO | YES |
CVE-2024-6457HIGH The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the ‘woof_author’ parameter in all versions up to, and i | Jul 16, 2024 | 7.5 | 35 | NO | NO |
CVE-2022-1916MEDIUM The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store WordPress plugin before 1.0.5 does not sanitise and escape a parameter before outputt | Jun 27, 2022 | 6.1 | 32 | NO | YES |
CVE-2021-25085MEDIUM The WOOF WordPress plugin before 1.2.6.3 does not sanitise and escape the woof_redraw_elements before outputing back in an admin page, leading to a Reflected Cross-Site Scripting | Feb 1, 2022 | 6.1 | 32 | NO | YES |
CVE-2024-8624CRITICAL The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to SQL Injection via the 'meta_key' attribute of the 'mdf_select_title' shortcode in all versions up t | Sep 24, 2024 | 9.9 | 31 | NO | NO |
CVE-2023-40010CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in realmag777 HUSKY – Products Filter for WooCommerce Professional.This issue aff | Dec 20, 2023 | 9.8 | 30 | NO | NO |
CVE-2024-50450CRITICAL Improper Control of Generation of Code ('Code Injection') vulnerability in RealMag777 MDTF wp-meta-data-filter-and-taxonomy-filter allows Code Injection.This issue affects MDTF: fr | Oct 28, 2024 | 9.8 | 27 | NO | NO |
CVE-2021-20781HIGH Cross-site request forgery (CSRF) vulnerability in WordPress Meta Data Filter & Taxonomies Filter versions prior to v.1.2.8 and versions prior to v.2.2.8 allows remote attackers to | Jul 14, 2021 | 8.8 | 27 | NO | NO |
CVE-2024-30456HIGH Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WPCS.This issue affects WPCS: from n/a through 1.2.0.1. | Mar 29, 2024 | 8.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (85 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pluginus.
Media articles that mention a CVE ID that affects a product developed by Pluginus — matched by CVE ID, not by vendor name.