WordPress Plugin Vulnerabilities

Active Products Tables for WooCommerce < 1.0.6.8 - Unauthenticated Arbitrary Filter Call

Description

The plugin is vulnerable to unauthorized filter calling due to insufficient restrictions on the get_smth() function. This makes it possible for unauthenticated attackers to call arbitrary WordPress filters with a single parameter.

Affects Plugins

References

Classification

Type
NO AUTHORISATION
CWE
CVSS

Miscellaneous

Original Researcher
Arkadiusz Hydzik
Verified
No

Timeline

Publicly Published
2025-03-25 (about 1 year ago)
Added
2025-03-26 (about 1 year ago)
Last Updated
2025-03-26 (about 1 year ago)

Other