CVE-2024-6365
CRITICAL EXPLOITEDProduct Table by WBW < 2.0.1 - Unauthenticated Remote Code Execution via saveCustomTitle Function
Title source: llmExploitation Summary
CVE-2024-6365 has been observed exploited in the wild (reported by VulnCheck KEV).
Description
The Product Table by WBW plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.1 via the 'saveCustomTitle' function. This is due to missing authorization and lack of sanitization of appended data in the languages/customTitle.php file. This makes it possible for unauthenticated attackers to execute code on the server.
References (4)
Core 4
Core References
Scores
CVSS v3
9.8
EPSS
0.0121
EPSS Percentile
64.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
VulnCheck KEV
2024-07-08
CWE
CWE-94
Status
published
Products (2)
woobewoo/Product Table by WBW
< 2.0.1
woobewoo/Product Table for WooCommerce by WBW
< 2.0.1
Published
Jul 09, 2024
Tracked Since
Feb 18, 2026