nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-6365 CVE-2024-6365
CRITICAL
Product Table by WBW <= 2.0.1 - Unauthenticated Remote Code Execution
Record summary
CVE-2024-6365 has a selected CVSS score of 9.8 (critical).
Description
The Product Table by WBW plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.1 via the 'saveCustomTitle' function. This is due to missing authorization and lack of sanitization of appended data in the languages/customTitle.php file. This makes it possible for unauthenticated attackers to execute code on the server.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jul 8, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 9, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
Product Table plugin for WordPressBrowse WBW / Product Table plugin for WordPress | VulnCheck | Version data not supplied | |
Product Table for WooCommerce by WBWBrowse woobewoo / Product Table for WooCommerce by WBWDefault status: unaffected | CVE List | Through 2.0.1 | affected |
product_table_by_wbwBrowse woobewoo / product_table_by_wbwDefault status: unknown | CVE List | Through 2.0.1 | affected |
References
5plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/browser/woo-product-tables/trunk/languages/customTitle.php plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/browser/woo-product-tables/trunk/modules/wootablepress/models/wootablepress.php plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset/3113335 wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/ba84711f-bdbe-46d3-a9a3-cc2b1dcefd1a?source=cve