Extension WordPress

Vulnérabilités Active Products Tables for WooCommerce. Use constructor to create tables

Cette page rassemble les failles publiées pour Active Products Tables for WooCommerce. Use constructor to create tables, leurs plages de versions affectées et les correctifs signalés dans la base locale.

16Vulnérabilités
1Critiques
16Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Active Products Tables for WooCommerce. Use constructor to create tables

16 fiches

CVE-2026-57409 Élevée · 7,2
Active Products Tables for WooCommerce. Use constructor to create tables

Active Products Tables for WooCommerce. Use constructor to create tables <= 1.1.0 – Unauthenticated Stored Cross-Site Scripting

The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-1.1.0

Correctif

1.1.1

Publication

08/07/2026

CVE-2026-42761 Élevée · 7,5
Active Products Tables for WooCommerce. Use constructor to create tables

Active Products Tables for WooCommerce. Use constructor to create tables <= 1.0.9 – Unauthenticated SQL Injection

The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.9 due to insufficient escaping on the user supplied parameter and lack of…

Versions affectées

*-1.0.9

Correctif

1.1.0

Publication

01/06/2026

CVE-2026-42727 Élevée · 7,5
Active Products Tables for WooCommerce. Use constructor to create tables

Active Products Tables for WooCommerce. Use constructor to create tables <= 1.0.8 – Unauthenticated SQL Injection

The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.8 due to insufficient escaping on the user supplied parameter and lack of…

Versions affectées

*-1.0.8

Correctif

1.0.9

Publication

19/05/2026

CVE-2026-32450 Moyenne · 6,4
Active Products Tables for WooCommerce. Use constructor to create tables

Active Products Tables for WooCommerce. Use constructor to create tables <= 1.0.7 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.7 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-1.0.7

Correctif

1.0.8

Publication

10/03/2026

CVE-2025-48266 Moyenne · 6,4
Active Products Tables for WooCommerce. Use constructor to create tables

Active Products Tables for WooCommerce <= 1.0.6.8 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Active Products Tables for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

Versions affectées

*-1.0.6.8

Correctif

1.0.6.9

Publication

19/05/2025

CVE-2025-1514 Élevée · 7,3
Active Products Tables for WooCommerce. Use constructor to create tables

Active Products Tables for WooCommerce <= 1.0.6.7 – Unauthenticated Arbitrary Filter Call

The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to unauthorized filter calling due to insufficient restrictions on the get_smth() function in all versions up to, and including, 1.0.6.7. This makes…

Versions affectées

*-1.0.6.7

Correctif

1.0.6.8

Publication

25/03/2025

CVE-2025-0864 Moyenne · 6,1
Active Products Tables for WooCommerce. Use constructor to create tables

Active Products Tables for WooCommerce. Use constructor to create tables <= 1.0.6.6 – Reflected Cross-Site Scripting

The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcodes_set' parameter in all versions up to, and including, 1.0.6.6 due to insufficient input sanitization and…

Versions affectées

*-1.0.6.6

Correctif

1.0.6.7

Publication

17/02/2025

CVE-2024-10959 Élevée · 7,3
Active Products Tables for WooCommerce. Use constructor to create tables

Active Products Tables for WooCommerce. Use constructor to create tables <= 1.0.6.5 – Unauthenticated Arbitrary Shortcode Execution via woot_get_smth

The The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to arbitrary shortcode execution via woot_get_smth AJAX action in all versions up to, and including, 1.0.6.5. This is due to the…

Versions affectées

*-1.0.6.5

Correctif

1.0.6.6

Publication

09/12/2024

CVE-2024-10168 Moyenne · 6,4
Active Products Tables for WooCommerce. Use constructor to create tables

Active Products Tables for WooCommerce. Use constructor to create tables <= 1.0.6.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via woot_button Shortcode

The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woot_button shortcode in all versions up to, and including, 1.0.6.4 due to insufficient input sanitization…

Versions affectées

*-1.0.6.4

Correctif

1.0.6.5

Publication

06/11/2024

CVE-2024-35730 Moyenne · 6,1
Active Products Tables for WooCommerce. Use constructor to create tables

Active Products Tables for WooCommerce. Use constructor to create tables <= 1.0.6.3 – Reflected Cross-Site Scripting

The Active Products Tables for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.0.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…

Versions affectées

*-1.0.6.3

Correctif

1.0.6.4

Publication

06/06/2024

CVE-2024-32691 Moyenne · 6,5
Active Products Tables for WooCommerce. Use constructor to create tables

Active Products Tables for WooCommerce <= 1.0.6.2 – Missing Authorization

The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the get_smth() function in all versions up to,…

Versions affectées

*-1.0.6.2

Correctif

1.0.6.3

Publication

19/04/2024

CVE-2024-0796 Moyenne · 4,3
Active Products Tables for WooCommerce. Use constructor to create tables

Active Products Tables for WooCommerce. Professional products tables for WooCommerce store <= 1.0.6.1 – Cross-Site Request Forgery

The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.6.1. This is due to missing or incorrect nonce validation…

Versions affectées

*-1.0.6.1

Correctif

1.0.6.2

Publication

31/01/2024

CVE-2024-0797 Moyenne · 4,3
Active Products Tables for WooCommerce. Use constructor to create tables

Active Products Tables for WooCommerce. Professional products tables for WooCommerce store <= 1.0.6.1 – Missing Authorization

The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on several functions in all versions up to, and including,…

Versions affectées

*-1.0.6.1

Correctif

1.0.6.2

Publication

31/01/2024

CVE-2023-51505 Critique · 9,8
Active Products Tables for WooCommerce. Use constructor to create tables

Active Products Tables for WooCommerce <= 1.0.6 – Unauthenticated PHP Object Injection

The Active Products Tables for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.6 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a…

Versions affectées

*-1.0.6

Correctif

1.0.6.1

Publication

27/12/2023

CVE-2023-51480 Moyenne · 6,4
Active Products Tables for WooCommerce. Use constructor to create tables

Active Products Tables for WooCommerce <= 1.0.6 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.0.6 due to insufficient input sanitization…

Versions affectées

*-1.0.6

Correctif

1.0.6.1

Publication

27/12/2023

CVE-2022-1916 Moyenne · 6,1
Active Products Tables for WooCommerce. Use constructor to create tables

Active Products Tables for WooCommerce <= 1.0.4 – Reflected Cross-Site Scripting

The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store WordPress plugin before 1.0.5 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated…

Versions affectées

*-1.0.4

Correctif

1.0.5

Publication

01/06/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités