Executive brief
A security vulnerability exists in the Active Products Tables for WooCommerce plugin, which is used to display product data in customizable tables on WordPress e-commerce sites. An attacker can exploit this flaw to gain unauthorized access to the website's database, potentially exposing sensitive customer information or business data. This issue can be exploited remotely without requiring any login credentials or user interaction.
Technical details
The Active Products Tables for WooCommerce plugin (profit-products-tables-for-woocommerce) by RealMag777 is vulnerable to Blind SQL Injection due to improper neutralization of special elements used in SQL commands. The flaw exists in versions up to and including 1.0.9. An unauthenticated attacker can send specially crafted network requests to trigger the vulnerability, allowing them to infer data from the database through boolean-based or time-based blind techniques. According to the CVSS score, the impact includes high confidentiality loss and low availability impact. Users are advised to update to a version higher than 1.0.9 if available.
Affected products
- RealMag777 Active Products Tables for WooCommerce (profit-products-tables-for-woocommerce) <= 1.0.9
Timeline
- 2026-05-27: disclosed
- 2026-05-27: advisory