Description
The Active Woot Products Tables for WooCommerce. 100% FREE  WordPress plugin before 2.1.3 does not have authorisation and CSRF checks in some of its AJAX actions, allowing any authenticated users, such as subscriber, to change the title of arbitrary posts, pages and products.
Published: 2026-09-17
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Integrity Compromise
Action: Patch
AI Analysis

Impact

The Active Woot Products Tables for WooCommerce plugin before version 2.1.3 is missing authorisation and CSRF checks in several of its AJAX actions. An authenticated user with the subscriber role can submit requests that change the title of any post, page, or product on the site. This capability allows an attacker to alter the visible content of the site, potentially misrepresenting products or defacing pages, which directly compromises data integrity.

Affected Systems

WordPress installations running the Active Woot Products Tables for WooCommerce plugin version earlier than 2.1.3 are affected. The vulnerability is exploitable through the plugin’s AJAX endpoint that accepts the action woot_update_attachment. Sites that host posts, pages, or WooCommerce products and integrate this plugin are at risk.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity. The EPSS score of less than 1% implies that the likelihood of exploitation is low. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires only an authenticated subscriber account; the absence of CSRF protection means that a crafted request can be sent even without user interaction. As a result, the overall risk is moderate but the probability of real‑world exploitation remains low.

Generated by OpenCVE AI on September 18, 2026 at 04:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Active Woot Products Tables for WooCommerce plugin to version 2.1.3 or later, which includes proper authorisation and CSRF checks.
  • Revoke the subscriber role’s capability to trigger the woot_update_attachment AJAX action by adjusting role permissions in WordPress.
  • Deploy a security plugin that restricts or monitors AJAX action permissions to block unauthorized requests to sensitive endpoints.

Generated by OpenCVE AI on September 18, 2026 at 04:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-352
CWE-862
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Active Woot Products Tables for WooCommerce. 100% FREE  WordPress plugin before 2.1.3 does not have authorisation and CSRF checks in some of its AJAX actions, allowing any authenticated users, such as subscriber, to change the title of arbitrary posts, pages and products.
Title Active Products Tables for WooCommerce < 2.1.3 - Subscriber+ Arbitrary Post Title Modification via woot_update_attachment
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-17T12:26:43.212Z

Reserved: 2026-09-14T16:11:02.393Z

Link: CVE-2026-91009

cve-icon Vulnrichment

Updated: 2026-09-17T12:10:05.607Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T06:16:52.640

Modified: 2026-09-18T19:08:32.830

Link: CVE-2026-91009

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T05:00:04Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)

  • CWE-862

    Missing Authorization