Known vulnerabilities in WCAPF – Ajax Product Filter for WooCommerce
Filter WooCommerce products by category, tag, attribute, price, rating, author, meta fields, and keyword using AJAX.
1Reported vulnerabilities
7.5Highest CVSS score
4.4.0Latest version
8,000+Active installs
What to do now
Update WCAPF – Ajax Product Filter for WooCommerce to 4.3.0 or later.
1 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2026-3396 | High | 1.5% | 4.2.3 and earlier | 4.3.0 |
April 7, 2026 |