Active Products Tables for WooCommerce < 2.1.3 - Subscriber+ Arbitrary Post Title Modification via woot_update_attachment
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 4.3epss 0.1%
exploitation probability
0.1%top 97% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The Active Woot Products Tables for WooCommerce. 100% FREE WordPress plugin before 2.1.3 does not have authorisation and CSRF checks in some of its AJAX actions, allowing any authenticated users, such as subscriber, to change the title of arbitrary posts, pages and products.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Affected products
Unknown · Active Woot Products Tables for WooCommerce. 100% FREEpublic PoCs found — 1
cve_referencewpscan.com/vulnerability/9a45333a-2db3-4695-9b1d-3677d31288f0/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.