Impact
The Active Woot Products Tables for WooCommerce plugin before version 2.1.3 is missing authorisation and CSRF checks in several of its AJAX actions. An authenticated user with the subscriber role can submit requests that change the title of any post, page, or product on the site. This capability allows an attacker to alter the visible content of the site, potentially misrepresenting products or defacing pages, which directly compromises data integrity.
Affected Systems
WordPress installations running the Active Woot Products Tables for WooCommerce plugin version earlier than 2.1.3 are affected. The vulnerability is exploitable through the plugin’s AJAX endpoint that accepts the action woot_update_attachment. Sites that host posts, pages, or WooCommerce products and integrate this plugin are at risk.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity. The EPSS score of less than 1% implies that the likelihood of exploitation is low. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires only an authenticated subscriber account; the absence of CSRF protection means that a crafted request can be sent even without user interaction. As a result, the overall risk is moderate but the probability of real‑world exploitation remains low.
OpenCVE Enrichment