plugin

Pricing Table By Supsystic Vulnerabilities

18 known security issues reported for the Pricing Table By Supsystic WordPress plugin. Most recent disclosed May 17, 2024.

4 high 1 medium 1 low

Running Pricing Table By Supsystic on your site? Check whether your installed version is affected.

Scan your site free

Pricing Table by Supsystic [pricing-table-by-supsystic] < 1.9.13

unknown

[en] Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Supsystic Pricing Table by Supsystic allows Code Injection.This issue affects Pricing Table by Supsystic: from n/a through 1.9.12.

Affected:
up to 1.9.13
Fixed in:
1.9.13
Disclosed:
May 17, 2024

CVE-2024-32790 on NVD →

Pricing Table by Supsystic <= 1.9.12 - Authenticated (Admin+) Content Injection

low

The Pricing Table by Supsystic plugin for WordPress is vulnerable to content injection in all versions up to, and including, 1.9.12. This makes it possible for authenticated attackers, with admin-level access and above, to inject arbitrary content. This is not a security issue by default, however, administrators can g...

CVSS:
2.7
Affected:
up to 1.9.12
Fixed in:
1.9.13
Disclosed:
Apr 22, 2024

CVE-2024-32790 on NVD →

Pricing Table by Supsystic [pricing-table-by-supsystic] < 1.9.5

unknown

[en] The Pricing Table by Supsystic WordPress plugin before 1.9.5 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting

Affected:
up to 1.9.5
Fixed in:
1.9.5
Disclosed:
Apr 25, 2022

CVE-2021-46782 on NVD →

Pricing Table by Supsystic <= 1.9.4 - Reflected Cross-Site Scripting

medium

The Pricing Table by Supsystic WordPress plugin before 1.9.5 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting

CVSS:
6.1
Affected:
up to 1.9.4
Fixed in:
1.9.5
Disclosed:
Apr 9, 2022

CVE-2021-46782 on NVD →

Pricing Table by Supsystic <= 1.8.8 - Boolean-Based Blind SQL Injections

high

The Pricing Table by Supsystic plugin for WordPress is vulnerable to boolean-based blind SQL Injection via the ‘sidx’ parameter in versions up to, and including, 1.8.8 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for au...

CVSS:
8.8
Affected:
up to 1.8.8
Fixed in:
1.8.9
Disclosed:
Feb 8, 2021

Pricing Table by Supsystic [pricing-table-by-supsystic] < 1.8.9

unknown

SQL injection (SQLi) vulnerability found by Erik David Martin in WordPress Pricing Table by Supsystic plugin (versions <= 1.8.8).

Affected:
up to 1.8.9
Fixed in:
1.8.9
Disclosed:
Feb 8, 2021

Pricing Table by Supsystic [pricing-table-by-supsystic] < 1.9.0

unknown

Stored Cross-Site Scripting (XSS) vulnerability found by Erik David Martin in WordPress Pricing Table by Supsystic plugin (versions <= 1.8.9).

Affected:
up to 1.9.0
Fixed in:
1.9.0
Disclosed:
Feb 8, 2021

Pricing Table by Supsystic [pricing-table-by-supsystic] < 1.8.9

unknown

The Pricing Table by Supsystic plugin for WordPress is vulnerable to boolean-based blind SQL Injection via the ‘sidx’ parameter in versions up to, and including, 1.8.8 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for au...

Affected:
up to 1.8.9
Fixed in:
1.8.9
Disclosed:
Feb 8, 2021

Pricing Table by Supsystic [pricing-table-by-supsystic] < 1.8.2

unknown

[en] An issue was discovered on Realtek RTL8195AM, RTL8711AM, RTL8711AF, and RTL8710AF devices before 2.0.6. A stack-based buffer overflow exists in the client code that takes care of WPA2's 4-way-handshake via a malformed EAPOL-Key packet with a long keydata buffer.

Affected:
up to 1.8.2
Fixed in:
1.8.2
Disclosed:
Jul 6, 2020

CVE-2020-9395 on NVD →

Pricing Table by Supsystic [pricing-table-by-supsystic] < 1.8.2

unknown

[en] An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. Because there is no permission check on the ImportJSONTable, createFromTpl, and getJSONExportTable endpoints, unauthenticated users can retrieve pricing table information, create new tables, or import/modify a table.

Affected:
up to 1.8.2
Fixed in:
1.8.2
Disclosed:
Mar 23, 2020

CVE-2020-9392 on NVD →

Pricing Table by Supsystic <= 1.8.1 - Cross-Site Request Forgery to Cross-Site Scripting and Setting Changes

high

An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows CSRF.

CVSS:
8.8
Affected:
up to 1.8.1
Fixed in:
1.8.2
Disclosed:
Feb 25, 2020

CVE-2020-9394 on NVD →

Pricing Table by Supsystic <= 1.8.1 - Missing Authorization on AJAX Actions

high

An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. Because there is no permission check on the ImportJSONTable, createFromTpl, and getJSONExportTable endpoints, unauthenticated users can retrieve pricing table information, create new tables, or import/modify a table.

CVSS:
7.3
Affected:
up to 1.8.1
Fixed in:
1.8.2
Disclosed:
Feb 25, 2020

CVE-2020-9392 on NVD →

Pricing Table by Supsystic <= 1.8.1 - Unauthenticated Stored Cross-Site Scripting

high

An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows XSS.

CVSS:
7.2
Affected:
up to 1.8.1
Fixed in:
1.8.2
Disclosed:
Feb 25, 2020

CVE-2020-9393 on NVD →

Pricing Table by Supsystic [pricing-table-by-supsystic] < 1.8.2

unknown

[en] An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows XSS.

Affected:
up to 1.8.2
Fixed in:
1.8.2
Disclosed:
Feb 25, 2020

CVE-2020-9393 on NVD →

Pricing Table by Supsystic [pricing-table-by-supsystic] < 1.8.2

unknown

[en] An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows CSRF.

Affected:
up to 1.8.2
Fixed in:
1.8.2
Disclosed:
Feb 25, 2020

CVE-2020-9394 on NVD →

Pricing Table by Supsystic [pricing-table-by-supsystic] < 1.8.9

unknown

The GET parameter sidx and sord are used in a SQL statement without being sanitised when searching for pricing tables in the dashboard, leading to an authenticated SQL Injection issues.

Affected:
up to 1.8.9
Fixed in:
1.8.9

Pricing Table by Supsystic [pricing-table-by-supsystic] < 1.9.0

unknown

The label and data[html] POST parameter are not properly sanitised and escaped before being saved and output back in the page, leading to stored Cross-Site Scripting issues

Affected:
up to 1.9.0
Fixed in:
1.9.0

Pricing Table by Supsystic [pricing-table-by-supsystic] < 1.8.1

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 1.8.1
Fixed in:
1.8.1

CVE-2020-9396 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database