Confidence
Medium. Based on 21 public sources; official pricing figures were not published on reviewed pages
Pricing
$0
Free
ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
ProfessionalNot confirmed in reviewed sources
Sources & method
Analyzed 10/05/2026 - 10 sources - Poor track record: multiple RCE, SQL injection, LFI, and IDOR vulnerabilities disclosed 2025-2026.
official x3review x3security x3news x1
- CVE-2025-1661 — Remote Code Execution, RCE vulnerability in the HUSKY WooCommerce filter plugin, patched March 2025.
- CVE-2026-92969 — Unauthenticated Local File Inclusion, Unauthenticated LFI leading to RCE, disclosed September 2026.
- CVE-2025-11735 — Blind SQL Injection, Blind SQL injection in the HUSKY WooCommerce filter plugin.
- CVE-2026-18562 — September 2026 flaw, Vulnerability affecting the plugin on ~80,000 stores per vendor tracking.
- IDOR in v1.3.6.1, Insecure direct object reference allowing unsubscribe actions.
Comments
One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.
No comments yet.