PatchSiren cyber security CVE debrief
CVE-2026-91009 Active Woot CVE debrief
The Active Woot Products Tables for WooCommerce. 100% FREE WordPress plugin before 2.1.3 does not have authorisation and CSRF checks in some of its AJAX actions, allowing any authenticated users, such as subscriber, to change the title of arbitrary posts, pages and products. This vulnerability allows attackers to modify content without proper authorization, potentially disrupting content management and integrity. Defenders should assess exposure, especially in WordPress installations with subscriber-level users.
- Vendor
- Active Woot
- Product
- Active Woot Products Tables for WooCommerce
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-17
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-09-17
- Advisory updated
- 2026-09-18
Who should care
Defenders responsible for WordPress installations using the Active Woot Products Tables for WooCommerce plugin, especially those with subscriber-level authenticated users, should assess exposure and potential impact.
Why it matters
CVE-2026-91009 is a MEDIUM-severity vulnerability in the Active Woot Products Tables for WooCommerce plugin, allowing authenticated users to change titles of arbitrary content. Defenders should verify exposure, especially in WordPress installations with subscriber-level users, and prioritize updating to version 2.1.3 or later.
- Potential unauthorized title changes to posts, pages, and products by authenticated users
- Possible disruption to content management and integrity
Technical summary
The Active Woot Products Tables for WooCommerce plugin before version 2.1.3 lacks authorisation and CSRF checks in some AJAX actions. This allows any authenticated user, including subscribers, to change the title of arbitrary posts, pages, and products. The vulnerability has a CVSS score of 4.3 and is classified as MEDIUM severity. Defenders should prioritize verifying exposure of WordPress installations using the Active Woot Products Tables for WooCommerce plugin, especially those with subscriber-level authenticated users.
Defensive priority
Defenders should prioritize verifying exposure of WordPress installations using the Active Woot Products Tables for WooCommerce plugin, especially those with subscriber-level authenticated users, and assess the impact of potential title changes to arbitrary posts, pages, and products.
Recommended defensive actions
- Verify WordPress installations for the Active Woot Products Tables for WooCommerce plugin version 2.1.3 or later
- Assess exposure of subscriber-level authenticated users to potential title changes
- Implement CSRF checks for AJAX actions in the plugin
- Monitor for suspicious title changes to posts, pages, and products
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its CVSS score of 4.3 and MEDIUM severity. A source reference from WPScan is also available. The vulnerability has been confirmed in versions prior to 2.1.3 of the Active Woot Products Tables for WooCommerce plugin. Defenders should verify the presence of this plugin in their WordPress installations and check for updates to version 2.1.3 or later. Evidence is based on CVE and NVD data, with additional context from WPScan.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-91009 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-91009
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-91009 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-91009
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/9a45333a-2db3-4695-9b1d-3677d31288f0/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.