Impact
An unauthenticated SQL injection flaw exists in the WordPress Active Products Tables for WooCommerce plugin up to version 1.1.1. The vulnerability allows an attacker to send specially crafted database queries through plugin input fields without requiring user authentication, potentially exposing or manipulating sensitive data stored in the database and compromising the confidentiality, integrity, or availability of the affected site.
Affected Systems
WordPress installations that have installed the Active Products Tables for WooCommerce plugin version 1.1.1 or earlier. The affected vendor is RealMag777 and any site using the plugin under those versions is vulnerable. The latest plugin release, version 2.1.2, contains a fix.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical severity; the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The flaw can be exploited over the web by an unauthenticated attacker who can submit malicious SQL statements through plugin-provided input fields, leading to data disclosure or alteration. Because no authentication or special privileges are required, the likelihood of exploitation is high in environments that expose the plugin to the public web.
OpenCVE Enrichment