plugin

Profit Products Tables For Woocommerce Vulnerabilities

31 known security issues reported for the Profit Products Tables For Woocommerce WordPress plugin. Most recent disclosed Aug 7, 2026.

1 critical 6 high 10 medium

Running Profit Products Tables For Woocommerce on your site? Check whether your installed version is affected.

Scan your site free

Active Woot Products Tables for WooCommerce. 100% FREE  <= 1.1.1 - Unauthenticated SQL Injection

high

The Active Woot Products Tables for WooCommerce. 100% FREE  plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated att...

CVSS:
7.5
Affected:
up to 1.1.1
Fixed in:
2.1.2
Disclosed:
Aug 7, 2026

CVE-2026-66436 on NVD →

Active Products Tables for WooCommerce. Use constructor to create tables  <= 1.1.0 - Unauthenticated Stored Cross-Site Scripting

high

The Active Products Tables for WooCommerce. Use constructor to create tables  plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web...

CVSS:
7.2
Affected:
up to 1.1.0
Fixed in:
1.1.1
Disclosed:
Jul 8, 2026

CVE-2026-57409 on NVD →

Active Products Tables for WooCommerce. Use constructor to create tables  <= 1.0.9 - Unauthenticated SQL Injection

high

The Active Products Tables for WooCommerce. Use constructor to create tables  plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for u...

CVSS:
7.5
Affected:
up to 1.0.9
Fixed in:
1.1.0
Disclosed:
Jun 1, 2026

CVE-2026-42761 on NVD →

Active Products Tables for WooCommerce. Use constructor to create tables  <= 1.0.8 - Unauthenticated SQL Injection

high

The Active Products Tables for WooCommerce. Use constructor to create tables  plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for u...

CVSS:
7.5
Affected:
up to 1.0.8
Fixed in:
1.0.9
Disclosed:
May 19, 2026

CVE-2026-42727 on NVD →

Active Products Tables for WooCommerce. Use constructor to create tables  <= 1.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Active Products Tables for WooCommerce. Use constructor to create tables  plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level a...

CVSS:
6.4
Affected:
up to 1.0.7
Fixed in:
1.0.8
Disclosed:
Mar 10, 2026

CVE-2026-32450 on NVD →

Active Products Tables for WooCommerce <= 1.0.6.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Active Products Tables for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitr...

CVSS:
6.4
Affected:
up to 1.0.6.8
Fixed in:
1.0.6.9
Disclosed:
May 19, 2025

CVE-2025-48266 on NVD →

Active Products Tables for WooCommerce. Use constructor to create tables  [profit-products-tables-for-woocommerce] < 1.0.6.9

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 Active Products Tables for WooCommerce allows Stored XSS. This issue affects Active Products Tables for WooCommerce: from n/a through 1.0.6.8.

Affected:
up to 1.0.6.9
Fixed in:
1.0.6.9
Disclosed:
May 19, 2025

CVE-2025-48266 on NVD →

Active Products Tables for WooCommerce <= 1.0.6.7 - Unauthenticated Arbitrary Filter Call

high

The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to unauthorized filter calling due to insufficient restrictions on the get_smth() function in all versions up to, and including, 1.0.6.7. This makes it possible for unauthenticated attackers to call arbitrary...

CVSS:
7.3
Affected:
up to 1.0.6.7
Fixed in:
1.0.6.8
Disclosed:
Mar 25, 2025

CVE-2025-1514 on NVD →

Active Products Tables for WooCommerce. Use constructor to create tables <= 1.0.6.6 - Reflected Cross-Site Scripting

medium

The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcodes_set' parameter in all versions up to, and including, 1.0.6.6 due to insufficient input sanitization and output escaping. This makes it possible for unauth...

CVSS:
6.1
Affected:
up to 1.0.6.6
Fixed in:
1.0.6.7
Disclosed:
Feb 17, 2025

CVE-2025-0864 on NVD →

Active Products Tables for WooCommerce. Use constructor to create tables  [profit-products-tables-for-woocommerce] < 1.0.6.6

unknown

[en] The The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to arbitrary shortcode execution via woot_get_smth AJAX action in all versions up to, and including, 1.0.6.5. This is due to the software allowing users to execute an action that does not properly va...

Affected:
up to 1.0.6.6
Fixed in:
1.0.6.6
Disclosed:
Dec 10, 2024

CVE-2024-10959 on NVD →

Active Products Tables for WooCommerce. Use constructor to create tables <= 1.0.6.5 - Unauthenticated Arbitrary Shortcode Execution via woot_get_smth

high

The The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to arbitrary shortcode execution via woot_get_smth AJAX action in all versions up to, and including, 1.0.6.5. This is due to the software allowing users to execute an action that does not properly validat...

CVSS:
7.3
Affected:
up to 1.0.6.5
Fixed in:
1.0.6.6
Disclosed:
Dec 9, 2024

CVE-2024-10959 on NVD →

Active Products Tables for WooCommerce. Use constructor to create tables  [profit-products-tables-for-woocommerce] < 1.0.6.5

unknown

[en] The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woot_button shortcode in all versions up to, and including, 1.0.6.4 due to insufficient input sanitization and output escaping on user supplied attributes....

Affected:
up to 1.0.6.5
Fixed in:
1.0.6.5
Disclosed:
Nov 6, 2024

CVE-2024-10168 on NVD →

Active Products Tables for WooCommerce. Use constructor to create tables <= 1.0.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via woot_button Shortcode

medium

The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woot_button shortcode in all versions up to, and including, 1.0.6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This...

CVSS:
6.4
Affected:
up to 1.0.6.4
Fixed in:
1.0.6.5
Disclosed:
Nov 5, 2024

CVE-2024-10168 on NVD →

Active Products Tables for WooCommerce. Use constructor to create tables  [profit-products-tables-for-woocommerce] < 1.0.6.4

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in realmag777 Active Products Tables for WooCommerce allows Reflected XSS.This issue affects Active Products Tables for WooCommerce: from n/a through 1.0.6.3.

Affected:
up to 1.0.6.4
Fixed in:
1.0.6.4
Disclosed:
Jun 8, 2024

CVE-2024-35730 on NVD →

Active Products Tables for WooCommerce. Use constructor to create tables <= 1.0.6.3 - Reflected Cross-Site Scripting

medium

The Active Products Tables for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.0.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exe...

CVSS:
6.1
Affected:
up to 1.0.6.3
Fixed in:
1.0.6.4
Disclosed:
Jun 6, 2024

CVE-2024-35730 on NVD →

Active Products Tables for WooCommerce. Use constructor to create tables  [profit-products-tables-for-woocommerce] < 1.0.6.3

unknown

[en] Missing Authorization vulnerability in realmag777 Active Products Tables for WooCommerce.This issue affects Active Products Tables for WooCommerce: from n/a through 1.0.6.2.

Affected:
up to 1.0.6.3
Fixed in:
1.0.6.3
Disclosed:
Apr 22, 2024

CVE-2024-32691 on NVD →

Active Products Tables for WooCommerce <= 1.0.6.2 - Missing Authorization

medium

The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the get_smth() function in all versions up to, and including, 1.0.6.2. This makes it possible for unauthenticated attackers...

CVSS:
6.5
Affected:
up to 1.0.6.2
Fixed in:
1.0.6.3
Disclosed:
Apr 19, 2024

CVE-2024-32691 on NVD →

Active Products Tables for WooCommerce. Use constructor to create tables  [profit-products-tables-for-woocommerce] < 1.0.6.1

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 Active Products Tables for WooCommerce. Professional products tables for WooCommerce store allows Stored XSS.This issue affects Active Products Tables for WooCommerce. Professional products tables for W...

Affected:
up to 1.0.6.1
Fixed in:
1.0.6.1
Disclosed:
Feb 10, 2024

CVE-2023-51480 on NVD →

Active Products Tables for WooCommerce. Use constructor to create tables  [profit-products-tables-for-woocommerce] < 1.0.6.2

unknown

[en] The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on several functions in all versions up to, and including, 1.0.6.1. This makes it possible for subscribers and...

Affected:
up to 1.0.6.2
Fixed in:
1.0.6.2
Disclosed:
Feb 5, 2024

CVE-2024-0797 on NVD →

Active Products Tables for WooCommerce. Use constructor to create tables  [profit-products-tables-for-woocommerce] < 1.0.6.2

unknown

[en] The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.6.1. This is due to missing or incorrect nonce validation on several functions corresponding to AJAX actions. Thi...

Affected:
up to 1.0.6.2
Fixed in:
1.0.6.2
Disclosed:
Feb 5, 2024

CVE-2024-0796 on NVD →

Active Products Tables for WooCommerce. Professional products tables for WooCommerce store <= 1.0.6.1 - Cross-Site Request Forgery

medium

The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.6.1. This is due to missing or incorrect nonce validation on several functions corresponding to AJAX actions. This mak...

CVSS:
4.3
Affected:
up to 1.0.6.1
Fixed in:
1.0.6.2
Disclosed:
Jan 31, 2024

CVE-2024-0796 on NVD →

Active Products Tables for WooCommerce. Professional products tables for WooCommerce store <= 1.0.6.1 - Missing Authorization

medium

The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on several functions in all versions up to, and including, 1.0.6.1. This makes it possible for subscribers and highe...

CVSS:
4.3
Affected:
up to 1.0.6.1
Fixed in:
1.0.6.2
Disclosed:
Jan 31, 2024

CVE-2024-0797 on NVD →

Active Products Tables for WooCommerce. Use constructor to create tables  [profit-products-tables-for-woocommerce] < 1.0.6.1

unknown

[en] Deserialization of Untrusted Data vulnerability in realmag777 Active Products Tables for WooCommerce. Professional products tables for WooCommerce store.This issue affects Active Products Tables for WooCommerce. Professional products tables for WooCommerce store : from n/a through 1.0.6.

Affected:
up to 1.0.6.1
Fixed in:
1.0.6.1
Disclosed:
Dec 29, 2023

CVE-2023-51505 on NVD →

Active Products Tables for WooCommerce <= 1.0.6 - Unauthenticated PHP Object Injection

critical

The Active Products Tables for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.6 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. If a POP chain is present via an additional plugin or the...

CVSS:
9.8
Affected:
up to 1.0.6
Fixed in:
1.0.6.1
Disclosed:
Dec 27, 2023

CVE-2023-51505 on NVD →

Active Products Tables for WooCommerce <= 1.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping on user supplied attribute...

CVSS:
6.4
Affected:
up to 1.0.6
Fixed in:
1.0.6.1
Disclosed:
Dec 27, 2023

CVE-2023-51480 on NVD →

Active Products Tables for WooCommerce. Use constructor to create tables  [profit-products-tables-for-woocommerce] < 1.0.5

unknown

[en] The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store WordPress plugin before 1.0.5 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected cross...

Affected:
up to 1.0.5
Fixed in:
1.0.5
Disclosed:
Jun 27, 2022

CVE-2022-1916 on NVD →

Active Products Tables for WooCommerce <= 1.0.4 - Reflected Cross-Site Scripting

medium

The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store WordPress plugin before 1.0.5 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected cross-Site...

CVSS:
6.1
Affected:
up to 1.0.4
Fixed in:
1.0.5
Disclosed:
Jun 1, 2022

CVE-2022-1916 on NVD →

Active Products Tables for WooCommerce. Use constructor to create tables  [profit-products-tables-for-woocommerce] < 1.0.4

unknown

Reflected Cross-Scripting (XSS) vulnerability discovered in WordPress Active Products Tables for WooCommerce plugin (versions <= 1.0.3).

Affected:
up to 1.0.4
Fixed in:
1.0.4
Disclosed:
Sep 29, 2021

Active Products Tables for WooCommerce. Use constructor to create tables  [profit-products-tables-for-woocommerce] < 1.0.4

unknown

The plugin does not sanitise or escape some parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting issues

Affected:
up to 1.0.4
Fixed in:
1.0.4

Active Products Tables for WooCommerce. Use constructor to create tables  [profit-products-tables-for-woocommerce] < 1.0.6.7

unknown
Affected:
up to 1.0.6.7
Fixed in:
1.0.6.7

CVE-2025-0864 on NVD →

Active Products Tables for WooCommerce. Use constructor to create tables  [profit-products-tables-for-woocommerce] < 1.0.6.8

unknown
Affected:
up to 1.0.6.8
Fixed in:
1.0.6.8

CVE-2025-1514 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database