Description
Missing Authorization vulnerability in WC Product Table WooCommerce Product Table Lite wc-product-table-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Product Table Lite: from n/a through <= 3.8.7.
Published: 2025-01-24
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a missing authorization flaw in the WooCommerce Product Table Lite plugin that allows an attacker to exploit incorrectly configured access control settings. The flaw means that users who should not have access to certain product data or administrative features can obtain that information through the plugin's web interface. The primary impact is the disclosure or potential manipulation of product data, which can affect the confidentiality and integrity of the store’s catalog. The weakness is categorized as a Broken Access Control (CWE-862).

Affected Systems

Vendors and products affected are WC Product Table: WooCommerce Product Table Lite. Any installation of the plugin with a version of 3.8.7 or earlier is vulnerable. Upgrading to a later release (3.8.8 or above) removes the issue.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1% indicates that, at the time of this analysis, exploitation is considered unlikely, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via the web interface of the plugin, requiring authenticated access, though the specific prerequisites are not detailed in the description and are inferred from typical plugin behavior. The vulnerability can be exploited by users who otherwise would not have permission to view or modify product information if the plugin’s access controls are misconfigured.

Generated by OpenCVE AI on May 1, 2026 at 18:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WooCommerce Product Table Lite plugin to version 3.8.8 or later to eliminate the broken access control flaw.
  • Verify after the update that plugin features are restricted to appropriate WordPress user roles, ensuring that only authorized personnel can view or modify product data.
  • If immediate upgrade is not possible, limit access to the plugin’s administrative pages by applying role‑based access controls or IP filtering to prevent unauthorized users from exploiting the flaw.

Generated by OpenCVE AI on May 1, 2026 at 18:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3800 Missing Authorization vulnerability in WC Product Table WooCommerce Product Table Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WooCommerce Product Table Lite: from n/a through 3.8.7.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in WC Product Table WooCommerce Product Table Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WooCommerce Product Table Lite: from n/a through 3.8.7. Missing Authorization vulnerability in WC Product Table WooCommerce Product Table Lite wc-product-table-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Product Table Lite: from n/a through <= 3.8.7.
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Tue, 11 Feb 2025 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Wcproducttable
Wcproducttable woocommerce Product Table
CPEs cpe:2.3:a:wcproducttable:woocommerce_product_table:*:*:*:*:lite:wordpress:*:*
Vendors & Products Wcproducttable
Wcproducttable woocommerce Product Table

Fri, 24 Jan 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jan 2025 17:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in WC Product Table WooCommerce Product Table Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WooCommerce Product Table Lite: from n/a through 3.8.7.
Title WordPress WooCommerce Product Table Lite plugin <= 3.8.7 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Wcproducttable Woocommerce Product Table
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-12T20:31:06.495Z

Reserved: 2025-01-23T14:50:57.839Z

Link: CVE-2025-24596

cve-icon Vulnrichment

Updated: 2025-01-24T18:47:21.424Z

cve-icon NVD

Status : Modified

Published: 2025-01-24T18:15:36.657

Modified: 2026-06-17T08:59:17.437

Link: CVE-2025-24596

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T19:00:08Z

Weaknesses