Pricing Table Plugin <= 3.6 - Unauthenticated SQL Injection
critical
The Pricing Table WordPress plugin before 3.6.1 fails to properly sanitize and escape user supplied POST data before it is being interpolated in an SQL statement and then executed via an AJAX action available to unauthenticated users
- CVSS:
- 9.8
- Affected:
- up to 3.6
- Fixed in:
- 3.6.1
- Disclosed:
- Apr 25, 2022
CVE-2022-0867 on NVD →
Pricing Table Plugin - < 2.3 - Cross-Site Request Forgery
high
WordPress Pricing Table Plugin Plugin 2.2 has a Cross-Site Request Forgery vulnerability via in the core/views/arprice_import_export.php in the plugin's Import/Export admin page.
- CVSS:
- 8.8
- Affected:
- up to 2.3
- Fixed in:
- 2.3
- Disclosed:
- Aug 8, 2019
CVE-2019-14679 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database