Remote Code Execution Vulnerability in Product Table plugin for WordPress
CVE-2024-6365
What is CVE-2024-6365?
The WBW Product Table plugin for WordPress is exposed to a Remote Code Execution vulnerability, allowing unauthorized users to execute arbitrary code on the server. This vulnerabilities stem from the 'saveCustomTitle' function, which lacks necessary authorization checks and sanitization processes for data inputs, particularly in the languages/customTitle.php file. Attackers can exploit this flaw to compromise the server's integrity, emphasizing the need for immediate updates and security measures for all installations of version 2.0.1 and prior.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Product Table by WBW * <= 2.0.1
References
EPSS Score
37% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved