plugin

Woo Product Tables Vulnerabilities

4 known security issues reported for the Woo Product Tables WordPress plugin. Most recent disclosed Apr 1, 2025.

1 critical 1 high 2 medium

Running Woo Product Tables on your site? Check whether your installed version is affected.

Scan your site free

Product Table by WBW <= 2.1.4 - Reflected Cross-Site Scripting

medium

The Product Table by WBW plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.1.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can success...

CVSS:
6.1
Affected:
up to 2.1.4
Fixed in:
2.1.5
Disclosed:
Apr 1, 2025

CVE-2025-31086 on NVD →

Product Table by WBW <= 2.1.2 - Unuthenticated SQL Injection

high

The Product Table by WBW plugin for WordPress is vulnerable to SQL Injection via the 'additionalCondition' parameter in all versions up to, and including, 2.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthent...

CVSS:
7.5
Affected:
up to 2.1.2
Fixed in:
2.1.3
Disclosed:
Jan 22, 2025

CVE-2024-13234 on NVD →

Product Table by WBW <= 2.0.1 - Unauthenticated Remote Code Execution

critical

The Product Table by WBW plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.1 via the 'saveCustomTitle' function. This is due to missing authorization and lack of sanitization of appended data in the languages/customTitle.php file. This makes it possible for unauthenti...

CVSS:
9.8
Affected:
up to 2.0.1
Fixed in:
2.0.2
Disclosed:
Jul 8, 2024

CVE-2024-6365 on NVD →

Product Table by WBW <= 1.8.6 - Cross-Site Request Forgery via saveGroup

medium

The Product Table by WBW plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.6. This is due to missing or incorrect nonce validation on the saveGroup function. This makes it possible for unauthenticated attackers to modify product groups via a forged request granted th...

CVSS:
4.3
Affected:
up to 1.8.6
Fixed in:
1.8.7
Disclosed:
Dec 27, 2023

CVE-2023-51512 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database