PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-91009 Active Woot CVE debrief

The Active Woot Products Tables for WooCommerce. 100% FREE WordPress plugin before 2.1.3 does not have authorisation and CSRF checks in some of its AJAX actions, allowing any authenticated users, such as subscriber, to change the title of arbitrary posts, pages and products. This vulnerability allows attackers to modify content without proper authorization, potentially disrupting content management and integrity. Defenders should assess exposure, especially in WordPress installations with subscriber-level users.

Vendor
Active Woot
Product
Active Woot Products Tables for WooCommerce
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-17
Original CVE updated
2026-09-18
Advisory published
2026-09-17
Advisory updated
2026-09-18

Who should care

Defenders responsible for WordPress installations using the Active Woot Products Tables for WooCommerce plugin, especially those with subscriber-level authenticated users, should assess exposure and potential impact.

Why it matters

CVE-2026-91009 is a MEDIUM-severity vulnerability in the Active Woot Products Tables for WooCommerce plugin, allowing authenticated users to change titles of arbitrary content. Defenders should verify exposure, especially in WordPress installations with subscriber-level users, and prioritize updating to version 2.1.3 or later.

  • Potential unauthorized title changes to posts, pages, and products by authenticated users
  • Possible disruption to content management and integrity

Technical summary

The Active Woot Products Tables for WooCommerce plugin before version 2.1.3 lacks authorisation and CSRF checks in some AJAX actions. This allows any authenticated user, including subscribers, to change the title of arbitrary posts, pages, and products. The vulnerability has a CVSS score of 4.3 and is classified as MEDIUM severity. Defenders should prioritize verifying exposure of WordPress installations using the Active Woot Products Tables for WooCommerce plugin, especially those with subscriber-level authenticated users.

Defensive priority

Defenders should prioritize verifying exposure of WordPress installations using the Active Woot Products Tables for WooCommerce plugin, especially those with subscriber-level authenticated users, and assess the impact of potential title changes to arbitrary posts, pages, and products.

Recommended defensive actions

  • Verify WordPress installations for the Active Woot Products Tables for WooCommerce plugin version 2.1.3 or later
  • Assess exposure of subscriber-level authenticated users to potential title changes
  • Implement CSRF checks for AJAX actions in the plugin
  • Monitor for suspicious title changes to posts, pages, and products
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its CVSS score of 4.3 and MEDIUM severity. A source reference from WPScan is also available. The vulnerability has been confirmed in versions prior to 2.1.3 of the Active Woot Products Tables for WooCommerce plugin. Defenders should verify the presence of this plugin in their WordPress installations and check for updates to version 2.1.3 or later. Evidence is based on CVE and NVD data, with additional context from WPScan.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-91009 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-91009

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-91009 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-91009

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.