Product Table by WBW <= 2.1.4 - Reflected Cross-Site Scripting
medium
The Product Table by WBW plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.1.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can success...
- CVSS:
- 6.1
- Affected:
- up to 2.1.4
- Fixed in:
- 2.1.5
- Disclosed:
- Apr 1, 2025
CVE-2025-31086 on NVD →
Product Table by WBW <= 2.1.2 - Unuthenticated SQL Injection
high
The Product Table by WBW plugin for WordPress is vulnerable to SQL Injection via the 'additionalCondition' parameter in all versions up to, and including, 2.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthent...
- CVSS:
- 7.5
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.3
- Disclosed:
- Jan 22, 2025
CVE-2024-13234 on NVD →
Product Table by WBW <= 2.0.1 - Unauthenticated Remote Code Execution
critical
The Product Table by WBW plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.1 via the 'saveCustomTitle' function. This is due to missing authorization and lack of sanitization of appended data in the languages/customTitle.php file. This makes it possible for unauthenti...
- CVSS:
- 9.8
- Affected:
- up to 2.0.1
- Fixed in:
- 2.0.2
- Disclosed:
- Jul 8, 2024
CVE-2024-6365 on NVD →
Product Table by WBW <= 1.8.6 - Cross-Site Request Forgery via saveGroup
medium
The Product Table by WBW plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.6. This is due to missing or incorrect nonce validation on the saveGroup function. This makes it possible for unauthenticated attackers to modify product groups via a forged request granted th...
- CVSS:
- 4.3
- Affected:
- up to 1.8.6
- Fixed in:
- 1.8.7
- Disclosed:
- Dec 27, 2023
CVE-2023-51512 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database