First published: Tue Dec 10 2024(Updated: )
The The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to arbitrary shortcode execution via woot_get_smth AJAX action in all versions up to, and including, 1.0.6.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
WooCommerce Active Products Tables for WooCommerce | <=1.0.6.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-10959 is considered a high-severity vulnerability due to the potential for arbitrary shortcode execution.
To fix CVE-2024-10959, update the Active Products Tables for WooCommerce plugin to the latest version that addresses this vulnerability.
CVE-2024-10959 affects all versions of the Active Products Tables for WooCommerce plugin up to and including version 1.0.6.5.
The vulnerability in CVE-2024-10959 is caused by improper handling of user input, allowing for arbitrary shortcode execution via the woot_get_smth AJAX action.
Users of the Active Products Tables for WooCommerce plugin for WordPress are impacted by CVE-2024-10959 if they are using an affected version.