First published: Wed Mar 26 2025(Updated: )
The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to unauthorized filter calling due to insufficient restrictions on the get_smth() function in all versions up to, and including, 1.0.6.7. This makes it possible for unauthenticated attackers to call arbitrary WordPress filters with a single parameter.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
WooCommerce Active Products Tables for WooCommerce | <=1.0.6.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-1514 has a medium severity due to the potential for unauthorized access through insufficient restrictions.
To fix CVE-2025-1514, upgrade the Active Products Tables for WooCommerce plugin to version 1.0.6.8 or later.
All versions of the Active Products Tables for WooCommerce plugin up to and including 1.0.6.7 are affected by CVE-2025-1514.
CVE-2025-1514 can lead to unauthorized filter calling, potentially allowing attackers to access sensitive data.
Users of the Active Products Tables for WooCommerce plugin in their WordPress installations are primarily affected by CVE-2025-1514.