Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 Active Products Tables for WooCommerce profit-products-tables-for-woocommerce allows DOM-Based XSS.This issue affects Active Products Tables for WooCommerce: from n/a through <= 1.1.0.
Published: 2026-07-13
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of input during web page generation creates a DOM‑based cross‑site scripting flaw that lets an attacker inject arbitrary JavaScript into pages served by the Active Products Tables for WooCommerce plugin. This can enable session hijacking, defacement, or the execution of malicious payloads in the context of the affected site. Based on the description, it is inferred that an attacker would need to submit crafted data to the plugin’s product table fields or to URLs used by the plugin, triggering the XSS in the user’s browser.

Affected Systems

The vulnerability affects the RealMag777 Active Products Tables for WooCommerce plugin, impacting all releases from the initial version through version 1.1.0. Users running any of these versions are exposed if they permit untrusted inputs to be processed by the plugin.

Risk and Exploitability

The CVSS score of 7.1 signals a high level of impact less than 1 % indicates that exploitation is currently unlikely. The flaw is not listed in the CISA KEV catalog. Attackers could potentially trigger the XSS by submitting malicious content to product table fields or by leading to the execution of arbitrary code in the victim’s browser.

Generated by OpenCVE AI on July 31, 2026 at 11:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Active Products Tables for WooCommerce plugin to the latest version that removes the XSS flaw.
  • Restrict configuration and input of product table data to privileged administrators and sanitize any user‑provided content before rendering.
  • Implement a Content Security Policy that blocks inline scripts to mitigate the impact of the defect if the plugin cannot be immediately updated.

Generated by OpenCVE AI on July 31, 2026 at 11:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Realmag777
Realmag777 active Products Tables For Woocommerce
Wordpress
Wordpress wordpress
Vendors & Products Realmag777
Realmag777 active Products Tables For Woocommerce
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 Active Products Tables for WooCommerce profit-products-tables-for-woocommerce allows DOM-Based XSS.This issue affects Active Products Tables for WooCommerce: from n/a through <= 1.1.0.
Title WordPress Active Products Tables for WooCommerce plugin <= 1.1.0 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Realmag777 Active Products Tables For Woocommerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T16:07:52.367Z

Reserved: 2026-06-24T12:46:27.805Z

Link: CVE-2026-57409

cve-icon Vulnrichment

Updated: 2026-07-13T16:02:21.615Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:00:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')