Description
Missing Authorization vulnerability in BinaryCarpenter Free Woocommerce Product Table View free-product-table-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Free Woocommerce Product Table View: from n/a through <= 1.78.
Published: 2025-04-01
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

BinaryCarpenter’s Free Woocommerce Product Table View plugin contains a missing authorization flaw that allows attackers to bypass intended access controls and view product table data that should be restricted. The vulnerability is a broken access control weakness, identified as CWE‑862, which can lead to the unauthorized disclosure of product information and potentially associated pricing or inventory details. The impact is primarily a compromise of confidentiality for the information exposed through the plugin’s interface; availability or integrity are not directly affected according to the provided description.

Affected Systems

WordPress sites running the Free Woocommerce Product Table View plugin version 1.78 or earlier. All releases from the initial release through 1.78 are affected. The plugin is distributed by BinaryCarpenter and is listed as "Free Woocommerce Product Table View" in the CNA data.

Risk and Exploitability

The vulnerability has a CVSS score of 5.4, indicating moderate risk, and an EPSS score of < 1%, suggesting a very low likelihood of exploitation at present. It is not listed in the CISA KEV catalog. Attackers can likely exploit the flaw through unauthenticated HTTP requests to the plugin’s exposed endpoints, abusing the missing permission checks to retrieve product data. The attack vector is inferred to be a web application exploit rather than a local privilege escalation or denial of service.

Generated by OpenCVE AI on May 1, 2026 at 02:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Free Woocommerce Product Table View plugin to a version newer than 1.78, which contains the access control fix.
  • If an upgrade is not immediately possible, disable the plugin or restrict its access to authenticated users only by applying role-based access controls in WordPress.
  • Monitor web access logs for unusual requests to the plugin’s URLs and block any suspicious activity using web application firewall rules.

Generated by OpenCVE AI on May 1, 2026 at 02:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9264 Missing Authorization vulnerability in BinaryCarpenter Free Woocommerce Product Table View allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Free Woocommerce Product Table View: from n/a through 1.78.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in BinaryCarpenter Free Woocommerce Product Table View allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Free Woocommerce Product Table View: from n/a through 1.78. Missing Authorization vulnerability in BinaryCarpenter Free Woocommerce Product Table View free-product-table-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Free Woocommerce Product Table View: from n/a through <= 1.78.
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Tue, 01 Apr 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Apr 2025 15:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in BinaryCarpenter Free Woocommerce Product Table View allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Free Woocommerce Product Table View: from n/a through 1.78.
Title WordPress Free Woocommerce Product Table View plugin <= 1.78 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:12.228Z

Reserved: 2025-04-01T13:19:14.440Z

Link: CVE-2025-31757

cve-icon Vulnrichment

Updated: 2025-04-01T20:32:37.208Z

cve-icon NVD

Status : Deferred

Published: 2025-04-01T15:16:12.373

Modified: 2026-04-23T15:28:13.847

Link: CVE-2025-31757

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T02:30:06Z

Weaknesses