Vulnerability Analysis
Active Products Tables for WooCommerce < 2.1.3 - Subscriber+ Arbitrary Post Title Modification via woot_update_attachment
CVE-2026-91009
The Active Woot Products Tables for WooCommerce. 100% FREE WordPress plugin before 2.1.3 does not have authorisation and CSRF checks in some of its AJAX actions, allowing any authenticated users, such as subscriber, to change the title of arbitrary posts, pages and products.
No Active Exploit Signals
CVSS Base Score
4.3
MEDIUM
Exploitability:2.9
Impact Score:1.5
Temporal Score:-
EPSS:-
Threat Intelligence Signals
CISA KEV
No
KEV Date Added
—
Ransomware Use
—
KEV Due Date
—
VulnCheck In-the-Wild
No
Nuclei Template
No
EPSS Score
—
EPSS Percentile
—
GHSA ID
GitHub Severity
MODERATE
SSVC Exploitation
None
SSVC Automatable
No
Vulnerability Class
—
Identity & Timeline
| Status | - |
| Assigning Authority | - |
| Discovered Via | - |
| Record Completeness | - |
| CVSS Version / Source | - |
| Reserved | - |
| Published | - |
| Patch Date (date_public) | - |
| Exploit DB Date | - |
| First GitHub PoC Date | - |
| Last Updated | - |
| Time to Patch (Days to fix) | - |
| Exploit Release Gap | - |
| PoC Release Gap | - |
| Exploit DB References | None identified |
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| No affected products specified. | ||
Social Buzz