Go Pricing [go_pricing] < 3.4
unknown
[en] The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.3.19 via deserialization of untrusted input from the 'go_pricing' shortcode 'data' parameter. This allows authenticated attackers, with subscriber-level permissions an...
- Affected:
- up to 3.4
- Fixed in:
- 3.4
- Disclosed:
- May 24, 2023
CVE-2023-2500 on NVD →
Go Pricing - WordPress Responsive Pricing Tables <= 3.3.19 - Authenticated (Subscriber+) PHP Object Injection
high
The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.3.19 via deserialization of untrusted input from the 'go_pricing' shortcode 'data' parameter. This allows authenticated attackers, with subscriber-level permissions and abo...
- CVSS:
- 8.8
- Affected:
- up to 3.3.19
- Fixed in:
- 3.4
- Disclosed:
- May 23, 2023
CVE-2023-2500 on NVD →
Go Pricing - WordPress Responsive Pricing Tables <= 3.3.19 - Improper Authorization to Arbitrary File Upload
high
The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to unauthorized arbitrary file uploads due to an improper capability check on the 'validate_upload' function in versions up to, and including, 3.3.19. This makes it possible for authenticated attackers with a role that the administr...
- CVSS:
- 7.1
- Affected:
- up to 3.3.19
- Fixed in:
- 3.4
- Disclosed:
- May 23, 2023
CVE-2023-2496 on NVD →
Go Pricing - WordPress Responsive Pricing Tables <= 3.3.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 3.3.19 due to insufficient input sanitization and output escaping. This makes it possible for contributor-level attackers to inject arbitrary web script...
- CVSS:
- 6.4
- Affected:
- up to 3.3.19
- Fixed in:
- 3.4
- Disclosed:
- May 23, 2023
CVE-2023-2498 on NVD →
Go Pricing - WordPress Responsive Pricing Tables <= 3.3.19 - Missing Authorization to Limited Privilege Granting
medium
The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'process_postdata' function in versions up to, and including, 3.3.19. This makes it possible for authenticated attackers with a role that the administrato...
- CVSS:
- 4.6
- Affected:
- up to 3.3.19
- Fixed in:
- 3.4
- Disclosed:
- May 23, 2023
CVE-2023-2494 on NVD →
Go Pricing [go_pricing] < 3.4
unknown
[en] The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'process_postdata' function in versions up to, and including, 3.3.19. This makes it possible for authenticated attackers with a role that the adminis...
- Affected:
- up to 3.4
- Fixed in:
- 3.4
- Disclosed:
- May 23, 2023
CVE-2023-2494 on NVD →
Go Pricing [go_pricing] < 3.4
unknown
[en] The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to unauthorized arbitrary file uploads due to an improper capability check on the 'validate_upload' function in versions up to, and including, 3.3.19. This makes it possible for authenticated attackers with a role that the admi...
- Affected:
- up to 3.4
- Fixed in:
- 3.4
- Disclosed:
- May 23, 2023
CVE-2023-2496 on NVD →
Go Pricing [go_pricing] < 3.4
unknown
[en] The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 3.3.19 due to insufficient input sanitization and output escaping. This makes it possible for contributor-level attackers to inject arbitrary web s...
- Affected:
- up to 3.4
- Fixed in:
- 3.4
- Disclosed:
- May 23, 2023
CVE-2023-2498 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database