Executive brief
WooCommerce Product Table Lite is a WordPress plugin used to display store products in a searchable and sortable table format. A security flaw allows unauthenticated attackers to inject malicious scripts into the website. If a site administrator or visitor interacts with a specially crafted link or page, the attacker could potentially hijack sessions, redirect users to malicious sites, or deface the store.
Technical details
The WooCommerce Product Table Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) in versions up to and including 4.6.3. This is caused by improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated attacker can exploit this by tricking a user into clicking a malicious link or visiting a crafted URL. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, which can lead to session theft or unauthorized actions. The issue is resolved in version 4.6.4.
Affected products
- WC Product Table WooCommerce Product Table Lite <= 4.6.3
Timeline
- 2026-02-22: disclosed: Vulnerability reported by researcher daroo
- 2026-04-07: advisory: Patchstack published initial advisory
- 2026-04-07: patched: Version 4.6.4 released to address the vulnerability
- 2026-06-15: advisory: CVE published to NVD