Record summary

CVE-2024-6365 has a selected CVSS score of 9.8 (critical).

Description

The Product Table by WBW plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.1 via the 'saveCustomTitle' function. This is due to missing authorization and lack of sanitization of appended data in the languages/customTitle.php file. This makes it possible for unauthenticated attackers to execute code on the server.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jul 8, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 9, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus

Product Table plugin for WordPress

Browse WBW / Product Table plugin for WordPress
VulnCheckVersion data not supplied

Product Table for WooCommerce by WBW

Browse woobewoo / Product Table for WooCommerce by WBW

Default status: unaffected

CVE ListThrough 2.0.1affected

Default status: unknown

CVE ListThrough 2.0.1affected

References

5