Description
Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions.
Published: 2026-08-13
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated SQL injection flaw exists in the WordPress Active Products Tables for WooCommerce plugin up to version 1.1.1. The vulnerability allows an attacker to send specially crafted database queries through plugin input fields without requiring user authentication, potentially exposing or manipulating sensitive data stored in the database and compromising the confidentiality, integrity, or availability of the affected site.

Affected Systems

WordPress installations that have installed the Active Products Tables for WooCommerce plugin version 1.1.1 or earlier. The affected vendor is RealMag777 and any site using the plugin under those versions is vulnerable. The latest plugin release, version 2.1.2, contains a fix.

Risk and Exploitability

The CVSS score of 9.3 indicates a critical severity; the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The flaw can be exploited over the web by an unauthenticated attacker who can submit malicious SQL statements through plugin-provided input fields, leading to data disclosure or alteration. Because no authentication or special privileges are required, the likelihood of exploitation is high in environments that expose the plugin to the public web.

Generated by OpenCVE AI on August 13, 2026 at 16:19 UTC.

Remediation

Vendor Solution

Update the WordPress Active Products Tables for WooCommerce Plugin to the latest available version (at least 2.1.2).


OpenCVE Recommended Actions

  • Upgrade the Active Products Tables for WooCommerce plugin to version 2.1.2 or later.
  • Disable or restrict access to the plugin’s input forms from unauthenticated users, if possible.
  • Monitor database logs and review site logs for signs of unexpected queries or data changes to detect potential exploitation.

Generated by OpenCVE AI on August 13, 2026 at 16:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Realmag777
Realmag777 active Products Tables For Woocommerce
Wordpress
Wordpress wordpress
Vendors & Products Realmag777
Realmag777 active Products Tables For Woocommerce
Wordpress
Wordpress wordpress
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions.
Title WordPress Active Products Tables for WooCommerce plugin <= 1.1.1 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Realmag777 Active Products Tables For Woocommerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-13T15:27:01.129Z

Reserved: 2026-07-27T09:00:18.436Z

Link: CVE-2026-66436

cve-icon Vulnrichment

Updated: 2026-08-13T15:26:55.968Z

cve-icon NVD

Status : Received

Published: 2026-08-13T14:17:05.380

Modified: 2026-08-13T16:18:43.030

Link: CVE-2026-66436

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T16:30:03Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')