---
id: CVE-2026-91009
title: The Active Woot Products Tables for WooCommerce
summary: "The Active Woot Products Tables for WooCommerce. 100% FREE\_ WordPress plugin before 2.1.3 does not have authorisation and CSRF checks in some of its AJAX actions, allowing any authenticated users, such as subscriber, to change the title …"
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-352
  - CWE-862
product: Active Woot Products Tables for WooCommerce. 100% FREE
affected:
  - active_woot_products_tables_for_woocommerce._100_free >= 2.1.2 < 2.1.3
published: '2026-09-17'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:08:32.830'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91009'
references:
  - url: 'https://wpscan.com/vulnerability/9a45333a-2db3-4695-9b1d-3677d31288f0/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00142
epssPercentile: 0.02887
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-17T12:11:09.789461Z'
ingestedAt: '2026-09-17T06:12:17.971Z'
---

## Overview

The Active Woot Products Tables for WooCommerce. 100% FREE  WordPress plugin before 2.1.3 does not have authorisation and CSRF checks in some of its AJAX actions, allowing any authenticated users, such as subscriber, to change the title of arbitrary posts, pages and products.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
