Pricing Table by Supsystic [pricing-table-by-supsystic] < 1.9.13
unknown
[en] Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Supsystic Pricing Table by Supsystic allows Code Injection.This issue affects Pricing Table by Supsystic: from n/a through 1.9.12.
- Affected:
- up to 1.9.13
- Fixed in:
- 1.9.13
- Disclosed:
- May 17, 2024
CVE-2024-32790 on NVD →
Pricing Table by Supsystic <= 1.9.12 - Authenticated (Admin+) Content Injection
low
The Pricing Table by Supsystic plugin for WordPress is vulnerable to content injection in all versions up to, and including, 1.9.12. This makes it possible for authenticated attackers, with admin-level access and above, to inject arbitrary content. This is not a security issue by default, however, administrators can g...
- CVSS:
- 2.7
- Affected:
- up to 1.9.12
- Fixed in:
- 1.9.13
- Disclosed:
- Apr 22, 2024
CVE-2024-32790 on NVD →
Pricing Table by Supsystic [pricing-table-by-supsystic] < 1.9.5
unknown
[en] The Pricing Table by Supsystic WordPress plugin before 1.9.5 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting
- Affected:
- up to 1.9.5
- Fixed in:
- 1.9.5
- Disclosed:
- Apr 25, 2022
CVE-2021-46782 on NVD →
Pricing Table by Supsystic <= 1.9.4 - Reflected Cross-Site Scripting
medium
The Pricing Table by Supsystic WordPress plugin before 1.9.5 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting
- CVSS:
- 6.1
- Affected:
- up to 1.9.4
- Fixed in:
- 1.9.5
- Disclosed:
- Apr 9, 2022
CVE-2021-46782 on NVD →
Pricing Table by Supsystic <= 1.8.8 - Boolean-Based Blind SQL Injections
high
The Pricing Table by Supsystic plugin for WordPress is vulnerable to boolean-based blind SQL Injection via the ‘sidx’ parameter in versions up to, and including, 1.8.8 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for au...
- CVSS:
- 8.8
- Affected:
- up to 1.8.8
- Fixed in:
- 1.8.9
- Disclosed:
- Feb 8, 2021
Pricing Table by Supsystic [pricing-table-by-supsystic] < 1.8.9
unknown
SQL injection (SQLi) vulnerability found by Erik David Martin in WordPress Pricing Table by Supsystic plugin (versions <= 1.8.8).
- Affected:
- up to 1.8.9
- Fixed in:
- 1.8.9
- Disclosed:
- Feb 8, 2021
Pricing Table by Supsystic [pricing-table-by-supsystic] < 1.9.0
unknown
Stored Cross-Site Scripting (XSS) vulnerability found by Erik David Martin in WordPress Pricing Table by Supsystic plugin (versions <= 1.8.9).
- Affected:
- up to 1.9.0
- Fixed in:
- 1.9.0
- Disclosed:
- Feb 8, 2021
Pricing Table by Supsystic [pricing-table-by-supsystic] < 1.8.9
unknown
The Pricing Table by Supsystic plugin for WordPress is vulnerable to boolean-based blind SQL Injection via the ‘sidx’ parameter in versions up to, and including, 1.8.8 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for au...
- Affected:
- up to 1.8.9
- Fixed in:
- 1.8.9
- Disclosed:
- Feb 8, 2021
Pricing Table by Supsystic [pricing-table-by-supsystic] < 1.8.2
unknown
[en] An issue was discovered on Realtek RTL8195AM, RTL8711AM, RTL8711AF, and RTL8710AF devices before 2.0.6. A stack-based buffer overflow exists in the client code that takes care of WPA2's 4-way-handshake via a malformed EAPOL-Key packet with a long keydata buffer.
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.2
- Disclosed:
- Jul 6, 2020
CVE-2020-9395 on NVD →
Pricing Table by Supsystic [pricing-table-by-supsystic] < 1.8.2
unknown
[en] An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. Because there is no permission check on the ImportJSONTable, createFromTpl, and getJSONExportTable endpoints, unauthenticated users can retrieve pricing table information, create new tables, or import/modify a table.
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.2
- Disclosed:
- Mar 23, 2020
CVE-2020-9392 on NVD →
Pricing Table by Supsystic <= 1.8.1 - Cross-Site Request Forgery to Cross-Site Scripting and Setting Changes
high
An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows CSRF.
- CVSS:
- 8.8
- Affected:
- up to 1.8.1
- Fixed in:
- 1.8.2
- Disclosed:
- Feb 25, 2020
CVE-2020-9394 on NVD →
Pricing Table by Supsystic <= 1.8.1 - Missing Authorization on AJAX Actions
high
An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. Because there is no permission check on the ImportJSONTable, createFromTpl, and getJSONExportTable endpoints, unauthenticated users can retrieve pricing table information, create new tables, or import/modify a table.
- CVSS:
- 7.3
- Affected:
- up to 1.8.1
- Fixed in:
- 1.8.2
- Disclosed:
- Feb 25, 2020
CVE-2020-9392 on NVD →
Pricing Table by Supsystic <= 1.8.1 - Unauthenticated Stored Cross-Site Scripting
high
An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows XSS.
- CVSS:
- 7.2
- Affected:
- up to 1.8.1
- Fixed in:
- 1.8.2
- Disclosed:
- Feb 25, 2020
CVE-2020-9393 on NVD →
Pricing Table by Supsystic [pricing-table-by-supsystic] < 1.8.2
unknown
[en] An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows XSS.
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.2
- Disclosed:
- Feb 25, 2020
CVE-2020-9393 on NVD →
Pricing Table by Supsystic [pricing-table-by-supsystic] < 1.8.2
unknown
[en] An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows CSRF.
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.2
- Disclosed:
- Feb 25, 2020
CVE-2020-9394 on NVD →
Pricing Table by Supsystic [pricing-table-by-supsystic] < 1.8.9
unknown
The GET parameter sidx and sord are used in a SQL statement without being sanitised when searching for pricing tables in the dashboard, leading to an authenticated SQL Injection issues.
- Affected:
- up to 1.8.9
- Fixed in:
- 1.8.9
Pricing Table by Supsystic [pricing-table-by-supsystic] < 1.9.0
unknown
The label and data[html] POST parameter are not properly sanitised and escaped before being saved and output back in the page, leading to stored Cross-Site Scripting issues
- Affected:
- up to 1.9.0
- Fixed in:
- 1.9.0
Pricing Table by Supsystic [pricing-table-by-supsystic] < 1.8.1
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 1.8.1
- Fixed in:
- 1.8.1
CVE-2020-9396 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database