Wcproducttable develops WooCommerce plugins that extend product-table functionality for WordPress e-commerce stores, a moderately prominent component in the broad WordPress plugin ecosystem. The vendor's disclosed vulnerabilities skew toward serious outcomes and center on application-layer weaknesses including code injection, missing authorization checks, and cross-site request forgery, reflecting the challenges of integrating dynamic features into a shared hosting environment where plugin isolation is minimal. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wcproducttable over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-34902HIGH Unauthenticated Cross Site Scripting (XSS) in WooCommerce Product Table Lite <= 4.6.3 versions. | Jun 15, 2026 | 7.1 | 28 | NO | NO |
CVE-2025-24596CRITICAL Missing Authorization vulnerability in WC Product Table WooCommerce Product Table Lite wc-product-table-lite allows Exploiting Incorrectly Configured Access Control Security Levels | Jan 24, 2025 | 9.8 | 26 | NO | NO |
CVE-2023-47519HIGH Cross-Site Request Forgery (CSRF) vulnerability in WC Product Table WooCommerce Product Table Lite.This issue affects WooCommerce Product Table Lite: from n/a through 2.6.2. | Nov 18, 2023 | 8.8 | 26 | NO | NO |
CVE-2024-13472HIGH The The WooCommerce Product Table Lite plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.9.4. This is due to the software | Jan 31, 2025 | 7.3 | 21 | NO | NO |
CVE-2024-43128HIGH Improper Control of Generation of Code ('Code Injection') vulnerability in WC Product Table WooCommerce Product Table Lite allows Code Injection.This issue affects WooCommerce Prod | Aug 13, 2024 | 7.3 | 21 | NO | NO |
CVE-2024-10899HIGH The The WooCommerce Product Table Lite plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.8.6. This is due to the software | Nov 20, 2024 | 7.3 | 19 | NO | NO |
CVE-2024-6458MEDIUM The WooCommerce Product Table Lite plugin for WordPress is vulnerable to unauthorized post title modification due to a missing capability check on the wcpt_presets__duplicate_prese | Jul 27, 2024 | 6.4 | 19 | NO | NO |
CVE-2025-39602MEDIUM Missing Authorization vulnerability in WC Product Table WooCommerce Product Table Lite wc-product-table-lite allows Exploiting Incorrectly Configured Access Control Security Levels | Apr 16, 2025 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wcproducttable.
Media articles that mention a CVE ID that affects a product developed by Wcproducttable — matched by CVE ID, not by vendor name.