"value":"The The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to arbitrary shortcode execution via woot_get_smth AJAX action in all versions up to, and including, 1.0.6.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes."
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"CWE-94 Improper Control of Generation of Code ('Code Injection')",
"cweId":"CWE-94"
}
]
}
]
},
"affects":{
"vendor":{
"vendor_data":[
{
"vendor_name":"realmag777",
"product":{
"product_data":[
{
"product_name":"Active Products Tables for WooCommerce. Use constructor to create tables",