Cross-Site Scripting
4 records40%First: 2021. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 10 vulnerability records associated with Product Table & List Builder For WooCommerce, published between 2021 and 2026.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2021 | 1 | |
| 2023 | 1 | |
| 2024 | 3 | |
| 2025 | 3 | |
| 2026 | 2 |
| Severity | Records | Share |
|---|---|---|
| High | 4 | 40% |
| Medium | 6 | 60% |
First: 2021. Latest: 2026.
First: 2024. Latest: 2025.
First: 2023. Latest: 2023.
First: 2024. Latest: 2024.
First: 2026. Latest: 2026.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
4.6.44.6.33.9.63.9.53.9.03.8.73.8.63.1.02.4.0Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-4.6.3 | Product Table and List Builder for WooCommerce Lite <= 4.6.3 - Unauthenticated Stored Cross-Site Scripting | April 7, 2026 | 4.6.4 | High |
*-4.6.2 | Product Table and List Builder for WooCommerce Lite <= 4.6.2 - Unauthenticated Time-Based SQL Injection via 'search' Parameter | February 18, 2026 | 4.6.3 | High |
*-3.9.5 | WooCommerce Product Table Lite <= 3.9.5 - Missing Authorization | April 16, 2025 | 3.9.6 | Medium |
*-3.9.4 | WooCommerce Product Table Lite <= 3.9.4 - Unauthenticated Arbitrary Shortcode Execution & Reflected Cross-Site Scripting | January 30, 2025 | 3.9.5 | High |
*-3.8.7 | WooCommerce Product Table Lite <= 3.8.7 - Missing Authorization | January 24, 2025 | 3.9.0 | Medium |
*-3.8.6 | WooCommerce Product Table Lite <= 3.8.6 - Unauthenticated Arbitrary Shortcode Execution & Reflected Cross-Site Scripting | November 19, 2024 | 3.8.7 | High |
*-3.5.1 | WooCommerce Product Table Lite <= 3.5.1 - Unauthenticated Arbitrary Shortcode Execution | August 7, 2024 | 3.8.6 | Medium |
*-3.5.1 | WooCommerce Product Table Lite <= 3.5.1 - Missing Authorization to (Subscriber+) Stored Cross-Site Scripting | July 26, 2024 | 3.8.6 | Medium |
*-2.6.2 | WooCommerce Product Table Lite <= 2.6.2 - Cross-Site Request Forgery | November 7, 2023 | 3.1.0 | Medium |
*-2.3.0 | WooCommerce Product Table Lite <= 2.4.0 - Reflected Cross-Site Scripting | September 27, 2021 | 2.4.0 | Medium |
Selected source records
Published: April 7, 2026
Published: February 18, 2026
Published: April 16, 2025
Published: January 30, 2025
Published: January 24, 2025
Published: November 19, 2024
Published: August 7, 2024
Published: July 26, 2024
Published: February 18, 2026
Published: January 30, 2025
Published: November 19, 2024
Published: April 7, 2026
Published: July 26, 2024
Published: September 27, 2021
Published: January 24, 2025
Published: April 16, 2025
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.