Junglewise Threat Intelligence

CVE-2026-42727: RealMag777 Active Products Tables for WooCommerce SQL injection

CVE-2026-42727 · Severity: critical · CVSS 9.3 · Published 2026-05-27

Vendors: PluginUs.Net.

Executive brief

A vulnerability exists in the Active Products Tables for WooCommerce plugin, which is used to display and manage product data on WordPress e-commerce sites. An attacker can exploit this flaw to gain unauthorized access to the website's database, potentially leading to the theft of sensitive customer information or site data. This issue can be exploited remotely without requiring any login credentials.

Technical details

The Active Products Tables for WooCommerce plugin for WordPress is vulnerable to a Blind SQL Injection due to improper neutralization of special elements used in an SQL command. The flaw exists in versions up to and including 1.0.8. An unauthenticated remote attacker can exploit this by sending specially crafted requests to the server, allowing them to extract sensitive information from the database through inference techniques. The vulnerability has been addressed in version 1.0.9. The CVSS 3.1 score of 9.3 reflects the high impact on confidentiality and the lack of authentication requirements.

Affected products

  • RealMag777 (PluginUs.Net) Active Products Tables for WooCommerce (profit-products-tables-for-woocommerce) <= 1.0.8

Timeline

  • 2026-04-19: other: Reported by researcher endy
  • 2026-05-19: advisory: Patchstack advisory published
  • 2026-05-27: disclosed: CVE published to NVD dataset

References