Active Woot Products Tables for WooCommerce. 100% FREE <= 1.1.1 - Unauthenticated SQL Injection
high
The Active Woot Products Tables for WooCommerce. 100% FREE plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated att...
- CVSS:
- 7.5
- Affected:
- up to 1.1.1
- Fixed in:
- 2.1.2
- Disclosed:
- Aug 7, 2026
CVE-2026-66436 on NVD →
Active Products Tables for WooCommerce. Use constructor to create tables <= 1.1.0 - Unauthenticated Stored Cross-Site Scripting
high
The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web...
- CVSS:
- 7.2
- Affected:
- up to 1.1.0
- Fixed in:
- 1.1.1
- Disclosed:
- Jul 8, 2026
CVE-2026-57409 on NVD →
Active Products Tables for WooCommerce. Use constructor to create tables <= 1.0.9 - Unauthenticated SQL Injection
high
The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for u...
- CVSS:
- 7.5
- Affected:
- up to 1.0.9
- Fixed in:
- 1.1.0
- Disclosed:
- Jun 1, 2026
CVE-2026-42761 on NVD →
Active Products Tables for WooCommerce. Use constructor to create tables <= 1.0.8 - Unauthenticated SQL Injection
high
The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for u...
- CVSS:
- 7.5
- Affected:
- up to 1.0.8
- Fixed in:
- 1.0.9
- Disclosed:
- May 19, 2026
CVE-2026-42727 on NVD →
Active Products Tables for WooCommerce. Use constructor to create tables <= 1.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level a...
- CVSS:
- 6.4
- Affected:
- up to 1.0.7
- Fixed in:
- 1.0.8
- Disclosed:
- Mar 10, 2026
CVE-2026-32450 on NVD →
Active Products Tables for WooCommerce <= 1.0.6.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Active Products Tables for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitr...
- CVSS:
- 6.4
- Affected:
- up to 1.0.6.8
- Fixed in:
- 1.0.6.9
- Disclosed:
- May 19, 2025
CVE-2025-48266 on NVD →
Active Products Tables for WooCommerce. Use constructor to create tables [profit-products-tables-for-woocommerce] < 1.0.6.9
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 Active Products Tables for WooCommerce allows Stored XSS. This issue affects Active Products Tables for WooCommerce: from n/a through 1.0.6.8.
- Affected:
- up to 1.0.6.9
- Fixed in:
- 1.0.6.9
- Disclosed:
- May 19, 2025
CVE-2025-48266 on NVD →
Active Products Tables for WooCommerce <= 1.0.6.7 - Unauthenticated Arbitrary Filter Call
high
The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to unauthorized filter calling due to insufficient restrictions on the get_smth() function in all versions up to, and including, 1.0.6.7. This makes it possible for unauthenticated attackers to call arbitrary...
- CVSS:
- 7.3
- Affected:
- up to 1.0.6.7
- Fixed in:
- 1.0.6.8
- Disclosed:
- Mar 25, 2025
CVE-2025-1514 on NVD →
Active Products Tables for WooCommerce. Use constructor to create tables <= 1.0.6.6 - Reflected Cross-Site Scripting
medium
The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcodes_set' parameter in all versions up to, and including, 1.0.6.6 due to insufficient input sanitization and output escaping. This makes it possible for unauth...
- CVSS:
- 6.1
- Affected:
- up to 1.0.6.6
- Fixed in:
- 1.0.6.7
- Disclosed:
- Feb 17, 2025
CVE-2025-0864 on NVD →
Active Products Tables for WooCommerce. Use constructor to create tables [profit-products-tables-for-woocommerce] < 1.0.6.6
unknown
[en] The The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to arbitrary shortcode execution via woot_get_smth AJAX action in all versions up to, and including, 1.0.6.5. This is due to the software allowing users to execute an action that does not properly va...
- Affected:
- up to 1.0.6.6
- Fixed in:
- 1.0.6.6
- Disclosed:
- Dec 10, 2024
CVE-2024-10959 on NVD →
Active Products Tables for WooCommerce. Use constructor to create tables <= 1.0.6.5 - Unauthenticated Arbitrary Shortcode Execution via woot_get_smth
high
The The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to arbitrary shortcode execution via woot_get_smth AJAX action in all versions up to, and including, 1.0.6.5. This is due to the software allowing users to execute an action that does not properly validat...
- CVSS:
- 7.3
- Affected:
- up to 1.0.6.5
- Fixed in:
- 1.0.6.6
- Disclosed:
- Dec 9, 2024
CVE-2024-10959 on NVD →
Active Products Tables for WooCommerce. Use constructor to create tables [profit-products-tables-for-woocommerce] < 1.0.6.5
unknown
[en] The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woot_button shortcode in all versions up to, and including, 1.0.6.4 due to insufficient input sanitization and output escaping on user supplied attributes....
- Affected:
- up to 1.0.6.5
- Fixed in:
- 1.0.6.5
- Disclosed:
- Nov 6, 2024
CVE-2024-10168 on NVD →
Active Products Tables for WooCommerce. Use constructor to create tables <= 1.0.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via woot_button Shortcode
medium
The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woot_button shortcode in all versions up to, and including, 1.0.6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This...
- CVSS:
- 6.4
- Affected:
- up to 1.0.6.4
- Fixed in:
- 1.0.6.5
- Disclosed:
- Nov 5, 2024
CVE-2024-10168 on NVD →
Active Products Tables for WooCommerce. Use constructor to create tables [profit-products-tables-for-woocommerce] < 1.0.6.4
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in realmag777 Active Products Tables for WooCommerce allows Reflected XSS.This issue affects Active Products Tables for WooCommerce: from n/a through 1.0.6.3.
- Affected:
- up to 1.0.6.4
- Fixed in:
- 1.0.6.4
- Disclosed:
- Jun 8, 2024
CVE-2024-35730 on NVD →
Active Products Tables for WooCommerce. Use constructor to create tables <= 1.0.6.3 - Reflected Cross-Site Scripting
medium
The Active Products Tables for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.0.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exe...
- CVSS:
- 6.1
- Affected:
- up to 1.0.6.3
- Fixed in:
- 1.0.6.4
- Disclosed:
- Jun 6, 2024
CVE-2024-35730 on NVD →
Active Products Tables for WooCommerce. Use constructor to create tables [profit-products-tables-for-woocommerce] < 1.0.6.3
unknown
[en] Missing Authorization vulnerability in realmag777 Active Products Tables for WooCommerce.This issue affects Active Products Tables for WooCommerce: from n/a through 1.0.6.2.
- Affected:
- up to 1.0.6.3
- Fixed in:
- 1.0.6.3
- Disclosed:
- Apr 22, 2024
CVE-2024-32691 on NVD →
Active Products Tables for WooCommerce <= 1.0.6.2 - Missing Authorization
medium
The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the get_smth() function in all versions up to, and including, 1.0.6.2. This makes it possible for unauthenticated attackers...
- CVSS:
- 6.5
- Affected:
- up to 1.0.6.2
- Fixed in:
- 1.0.6.3
- Disclosed:
- Apr 19, 2024
CVE-2024-32691 on NVD →
Active Products Tables for WooCommerce. Use constructor to create tables [profit-products-tables-for-woocommerce] < 1.0.6.1
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 Active Products Tables for WooCommerce. Professional products tables for WooCommerce store allows Stored XSS.This issue affects Active Products Tables for WooCommerce. Professional products tables for W...
- Affected:
- up to 1.0.6.1
- Fixed in:
- 1.0.6.1
- Disclosed:
- Feb 10, 2024
CVE-2023-51480 on NVD →
Active Products Tables for WooCommerce. Use constructor to create tables [profit-products-tables-for-woocommerce] < 1.0.6.2
unknown
[en] The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on several functions in all versions up to, and including, 1.0.6.1. This makes it possible for subscribers and...
- Affected:
- up to 1.0.6.2
- Fixed in:
- 1.0.6.2
- Disclosed:
- Feb 5, 2024
CVE-2024-0797 on NVD →
Active Products Tables for WooCommerce. Use constructor to create tables [profit-products-tables-for-woocommerce] < 1.0.6.2
unknown
[en] The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.6.1. This is due to missing or incorrect nonce validation on several functions corresponding to AJAX actions. Thi...
- Affected:
- up to 1.0.6.2
- Fixed in:
- 1.0.6.2
- Disclosed:
- Feb 5, 2024
CVE-2024-0796 on NVD →
Active Products Tables for WooCommerce. Professional products tables for WooCommerce store <= 1.0.6.1 - Cross-Site Request Forgery
medium
The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.6.1. This is due to missing or incorrect nonce validation on several functions corresponding to AJAX actions. This mak...
- CVSS:
- 4.3
- Affected:
- up to 1.0.6.1
- Fixed in:
- 1.0.6.2
- Disclosed:
- Jan 31, 2024
CVE-2024-0796 on NVD →
Active Products Tables for WooCommerce. Professional products tables for WooCommerce store <= 1.0.6.1 - Missing Authorization
medium
The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on several functions in all versions up to, and including, 1.0.6.1. This makes it possible for subscribers and highe...
- CVSS:
- 4.3
- Affected:
- up to 1.0.6.1
- Fixed in:
- 1.0.6.2
- Disclosed:
- Jan 31, 2024
CVE-2024-0797 on NVD →
Active Products Tables for WooCommerce. Use constructor to create tables [profit-products-tables-for-woocommerce] < 1.0.6.1
unknown
[en] Deserialization of Untrusted Data vulnerability in realmag777 Active Products Tables for WooCommerce. Professional products tables for WooCommerce store.This issue affects Active Products Tables for WooCommerce. Professional products tables for WooCommerce store : from n/a through 1.0.6.
- Affected:
- up to 1.0.6.1
- Fixed in:
- 1.0.6.1
- Disclosed:
- Dec 29, 2023
CVE-2023-51505 on NVD →
Active Products Tables for WooCommerce <= 1.0.6 - Unauthenticated PHP Object Injection
critical
The Active Products Tables for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.6 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. If a POP chain is present via an additional plugin or the...
- CVSS:
- 9.8
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6.1
- Disclosed:
- Dec 27, 2023
CVE-2023-51505 on NVD →
Active Products Tables for WooCommerce <= 1.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping on user supplied attribute...
- CVSS:
- 6.4
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6.1
- Disclosed:
- Dec 27, 2023
CVE-2023-51480 on NVD →
Active Products Tables for WooCommerce. Use constructor to create tables [profit-products-tables-for-woocommerce] < 1.0.5
unknown
[en] The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store WordPress plugin before 1.0.5 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected cross...
- Affected:
- up to 1.0.5
- Fixed in:
- 1.0.5
- Disclosed:
- Jun 27, 2022
CVE-2022-1916 on NVD →
Active Products Tables for WooCommerce <= 1.0.4 - Reflected Cross-Site Scripting
medium
The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store WordPress plugin before 1.0.5 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected cross-Site...
- CVSS:
- 6.1
- Affected:
- up to 1.0.4
- Fixed in:
- 1.0.5
- Disclosed:
- Jun 1, 2022
CVE-2022-1916 on NVD →
Active Products Tables for WooCommerce. Use constructor to create tables [profit-products-tables-for-woocommerce] < 1.0.4
unknown
Reflected Cross-Scripting (XSS) vulnerability discovered in WordPress Active Products Tables for WooCommerce plugin (versions <= 1.0.3).
- Affected:
- up to 1.0.4
- Fixed in:
- 1.0.4
- Disclosed:
- Sep 29, 2021
Active Products Tables for WooCommerce. Use constructor to create tables [profit-products-tables-for-woocommerce] < 1.0.4
unknown
The plugin does not sanitise or escape some parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting issues
- Affected:
- up to 1.0.4
- Fixed in:
- 1.0.4
Active Products Tables for WooCommerce. Use constructor to create tables [profit-products-tables-for-woocommerce] < 1.0.6.7
unknown
- Affected:
- up to 1.0.6.7
- Fixed in:
- 1.0.6.7
CVE-2025-0864 on NVD →
Active Products Tables for WooCommerce. Use constructor to create tables [profit-products-tables-for-woocommerce] < 1.0.6.8
unknown
- Affected:
- up to 1.0.6.8
- Fixed in:
- 1.0.6.8
CVE-2025-1514 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database