CVE-2023-51505
CVE-2023-51505 is a critical-severity vulnerability in Pluginus Woot with a CVSS 3.x base score of 10.0. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-502.
Key facts
- Severity: Critical (CVSS 3.x base score 10.0)
- EPSS exploit prediction: 1% (49th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-502
- Affected product: Pluginus Woot
- Published:
- Last modified:
Description
Deserialization of Untrusted Data vulnerability in realmag777 Active Products Tables for WooCommerce. Professional products tables for WooCommerce store.This issue affects Active Products Tables for WooCommerce. Professional products tables for WooCommerce store : from n/a through 1.0.6.
Frequently asked questions
- What is CVE-2023-51505?
- Deserialization of Untrusted Data vulnerability in realmag777 Active Products Tables for WooCommerce. Professional products tables for WooCommerce store.This issue affects Active Products Tables for WooCommerce. Professional products tables for WooCommerce store : from n/a through 1.0.6.
- How severe is CVE-2023-51505?
- CVE-2023-51505 has a CVSS 3.x base score of 10.0, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2023-51505 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (49th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2023-51505?
- CVE-2023-51505 affects Pluginus Woot. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2023-51505?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- When was CVE-2023-51505 published?
- CVE-2023-51505 was published on 2023-12-29 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:pluginus:woot:*:*:*:*:*:wordpress:*:*
More vulnerabilities in Pluginus Woot
- CVE-2024-35730 — High (CVSS 7.1): Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in realmag777…
- CVE-2023-51480 — Medium (CVSS 6.5): Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 Active…
- CVE-2024-10168 — Medium (CVSS 6.4): The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to…
- CVE-2022-1916 — Medium (CVSS 6.1): The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store WordPress plugin before…
- CVE-2024-0797 — Medium (CVSS 4.3): The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store plugin for WordPress is…
- CVE-2024-0796 — Medium (CVSS 4.3): The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store plugin for WordPress is…
All CVEs affecting Pluginus Woot →
Other CWE-502 (Deserialization of Untrusted Data) vulnerabilities
- CVE-2026-69836 — Critical (CVSS 10.0): Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
- CVE-2026-17061 — Critical (CVSS 10.0): A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release…
- CVE-2026-11756 — Critical (CVSS 10.0): A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release…
- CVE-2026-41104 — Critical (CVSS 10.0): Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose…
- CVE-2026-43633 — Critical (CVSS 10.0): HestiaCP versions 1.9.0 through 1.9.4 contain a deserialization vulnerability in the web terminal component caused by a…
- CVE-2026-33819 — Critical (CVSS 10.0): Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network.
Browse all CWE-502 (Deserialization of Untrusted Data) vulnerabilities →