The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to unauthorized filter calling due to insufficient restrictions on the get_smth() function in all versions up to, and including, 1.0.6.7. This makes it possible for unauthenticated attackers to call arbitrary WordPress filters with a single parameter.
Metrics
Affected Vendors & Products
References
History
Wed, 26 Mar 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 26 Mar 2025 08:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to unauthorized filter calling due to insufficient restrictions on the get_smth() function in all versions up to, and including, 1.0.6.7. This makes it possible for unauthenticated attackers to call arbitrary WordPress filters with a single parameter. | |
Title | Active Products Tables for WooCommerce <= 1.0.6.7 - Unauthenticated Arbitrary Filter Call | |
Weaknesses | CWE-20 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-03-26T08:21:51.303Z
Updated: 2025-03-26T14:12:17.566Z
Reserved: 2025-02-20T19:48:58.712Z
Link: CVE-2025-1514

Updated: 2025-03-26T14:12:13.405Z

Status : Received
Published: 2025-03-26T09:15:15.950
Modified: 2025-03-26T09:15:15.950
Link: CVE-2025-1514

No data.