pluginus Vulnerabilities and Affected Products
Vulnerabilities associated with woot.
Products
Clear product- husky_-_products_filter_professional_for_woocommerce5 vulnerabilities
- wordpress_meta_data_and_taxonomies_filter4 vulnerabilities
- woot3 vulnerabilities
- wordpress_currency_switcher2 vulnerabilities
- fox_-_currency_switcher_professional_for_woocommerce1 vulnerability
- HUSKY – Products Filter for WooCommerce (formerly WOOF)1 vulnerability
- inpost_gallery1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-32691MEDIUM | WordPress Active Products Tables for WooCommerce plugin <= 1.0.6.2 - Broken Access Control vulnerabilityMissing Authorization vulnerability in realmag777 Active Products Tables for WooCommerce.This issue affects Active Products Tables for WooCommerce: from n/a through 1.0.6.2. CWE-862Apr 22, 2024 | CVSS5.3v3.1 | EPSS0.396% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-51505CRITICAL | WordPress Active Products Tables for WooCommerce Plugin <= 1.0.6 is vulnerable to PHP Object InjectionDeserialization of Untrusted Data vulnerability in realmag777 Active Products Tables for WooCommerce. Professional products tables for WooCommerce store.This issue affects Active Products Tables for WooCommerce. Professional products tables for WooCommerce store : from n/a through 1.0.6. CWE-502Dec 29, 2023 | CVSS10.0v3.1 | EPSS0.651% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-1916MEDIUM | Active Products Tables for WooCommerce < 1.0.5 - Reflected Cross-Site-ScriptingThe Active Products Tables for WooCommerce. Professional products tables for WooCommerce store WordPress plugin before 1.0.5 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected cross-Site Scripting | CVSS6.1v3.1 | EPSS1.87% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |