WBW Vulnerabilities and Affected Products
Vulnerabilities associated with Product Table plugin for WordPress.
Products
Clear product- Product Filter by WooBeWoo plugin for WordPress1 vulnerability
- Product Table by WBW1 vulnerability
- Product Table plugin for WordPress1 vulnerability
- WBW Product Table PRO1 vulnerability
- WooBeWoo Product Filter Pro1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-6365CRITICAL | Product Table by WBW <= 2.0.1 - Unauthenticated Remote Code ExecutionThe Product Table by WBW plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.1 via the 'saveCustomTitle' function. This is due to missing authorization and lack of sanitization of appended data in the languages/customTitle.php file. This makes it possible for unauthenticated attackers to execute code on the server. CWE-94Jul 9, 2024 | CVSS9.8v3.1 | EPSS1.21% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |