Junglewise Threat Intelligence

CVE-2026-57409: RealMag777 Active Products Tables for WooCommerce DOM XSS

CVE-2026-57409 · Severity: high · CVSS 7.1 · Published 2026-07-13

Vendors: RealMag777.

Executive brief

A vulnerability exists in the Active Products Tables for WooCommerce plugin, which is used to display product data in customizable tables on WordPress e-commerce sites. An attacker could trick a user into clicking a malicious link, allowing the attacker to execute unauthorized scripts in the user's browser. This could lead to the theft of sensitive session information, unauthorized actions performed on behalf of the user, or the display of fraudulent content on the website.

Technical details

The Active Products Tables for WooCommerce plugin (profit-products-tables-for-woocommerce) for WordPress is vulnerable to DOM-based Cross-Site Scripting (XSS) due to improper neutralization of input during web page generation. The flaw exists in versions up to and including 1.1.0. An unauthenticated remote attacker can exploit this by convincing a user to visit a specially crafted URL or perform a specific action, leading to the execution of arbitrary JavaScript in the context of the victim's browser session. This is classified as CWE-79 and has been addressed in version 1.1.1.

Affected products

  • RealMag777 Active Products Tables for WooCommerce (profit-products-tables-for-woocommerce) <= 1.1.0

Timeline

  • 2026-05-02: other: Reported by hhhai
  • 2026-07-08: patched: Version 1.1.1 released
  • 2026-07-13: disclosed: CVE published

References