Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-33554 | The The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to arbitrary shortcode execution via woot_get_smth AJAX action in all versions up to, and including, 1.0.6.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 10 Dec 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Realmag777
Realmag777 active Products Tables For Woocommerce |
|
| CPEs | cpe:2.3:a:realmag777:active_products_tables_for_woocommerce:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Realmag777
Realmag777 active Products Tables For Woocommerce |
|
| Metrics |
ssvc
|
Tue, 10 Dec 2024 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to arbitrary shortcode execution via woot_get_smth AJAX action in all versions up to, and including, 1.0.6.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. | |
| Title | Active Products Tables for WooCommerce. Use constructor to create tables <= 1.0.6.5 - Unauthenticated Arbitrary Shortcode Execution via woot_get_smth | |
| Weaknesses | CWE-94 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:31:29.392Z
Reserved: 2024-11-07T00:02:14.604Z
Link: CVE-2024-10959
Updated: 2024-12-10T15:00:40.615Z
Status : Deferred
Published: 2024-12-10T11:15:05.913
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-10959
No data.
OpenCVE Enrichment
No data.
EUVD