CVE-2024-0797

MEDIUM

WooCommerce <1.0.6.1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on several functions in all versions up to, and including, 1.0.6.1. This makes it possible for subscribers and higher to execute functions intended for admin use.

Scores

CVSS v3 4.3
EPSS 0.0042
EPSS Percentile 34.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (2)
pluginus/woot < 1.0.6.2
realmag777/Active Products Tables for WooCommerce. Use constructor to create tables < 1.0.6.1
Published Feb 05, 2024
Tracked Since Feb 18, 2026