plugin

Go Pricing Vulnerabilities

8 known security issues reported for the Go Pricing WordPress plugin. Most recent disclosed May 24, 2023.

2 high 2 medium

Running Go Pricing on your site? Check whether your installed version is affected.

Scan your site free

Go Pricing [go_pricing] < 3.4

unknown

[en] The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.3.19 via deserialization of untrusted input from the 'go_pricing' shortcode 'data' parameter. This allows authenticated attackers, with subscriber-level permissions an...

Affected:
up to 3.4
Fixed in:
3.4
Disclosed:
May 24, 2023

CVE-2023-2500 on NVD →

Go Pricing - WordPress Responsive Pricing Tables <= 3.3.19 - Authenticated (Subscriber+) PHP Object Injection

high

The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.3.19 via deserialization of untrusted input from the 'go_pricing' shortcode 'data' parameter. This allows authenticated attackers, with subscriber-level permissions and abo...

CVSS:
8.8
Affected:
up to 3.3.19
Fixed in:
3.4
Disclosed:
May 23, 2023

CVE-2023-2500 on NVD →

Go Pricing - WordPress Responsive Pricing Tables <= 3.3.19 - Improper Authorization to Arbitrary File Upload

high

The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to unauthorized arbitrary file uploads due to an improper capability check on the 'validate_upload' function in versions up to, and including, 3.3.19. This makes it possible for authenticated attackers with a role that the administr...

CVSS:
7.1
Affected:
up to 3.3.19
Fixed in:
3.4
Disclosed:
May 23, 2023

CVE-2023-2496 on NVD →

Go Pricing - WordPress Responsive Pricing Tables <= 3.3.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 3.3.19 due to insufficient input sanitization and output escaping. This makes it possible for contributor-level attackers to inject arbitrary web script...

CVSS:
6.4
Affected:
up to 3.3.19
Fixed in:
3.4
Disclosed:
May 23, 2023

CVE-2023-2498 on NVD →

Go Pricing - WordPress Responsive Pricing Tables <= 3.3.19 - Missing Authorization to Limited Privilege Granting

medium

The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'process_postdata' function in versions up to, and including, 3.3.19. This makes it possible for authenticated attackers with a role that the administrato...

CVSS:
4.6
Affected:
up to 3.3.19
Fixed in:
3.4
Disclosed:
May 23, 2023

CVE-2023-2494 on NVD →

Go Pricing [go_pricing] < 3.4

unknown

[en] The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'process_postdata' function in versions up to, and including, 3.3.19. This makes it possible for authenticated attackers with a role that the adminis...

Affected:
up to 3.4
Fixed in:
3.4
Disclosed:
May 23, 2023

CVE-2023-2494 on NVD →

Go Pricing [go_pricing] < 3.4

unknown

[en] The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to unauthorized arbitrary file uploads due to an improper capability check on the 'validate_upload' function in versions up to, and including, 3.3.19. This makes it possible for authenticated attackers with a role that the admi...

Affected:
up to 3.4
Fixed in:
3.4
Disclosed:
May 23, 2023

CVE-2023-2496 on NVD →

Go Pricing [go_pricing] < 3.4

unknown

[en] The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 3.3.19 due to insufficient input sanitization and output escaping. This makes it possible for contributor-level attackers to inject arbitrary web s...

Affected:
up to 3.4
Fixed in:
3.4
Disclosed:
May 23, 2023

CVE-2023-2498 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database