plugin

Stylish Price List Vulnerabilities

12 known security issues reported for the Stylish Price List WordPress plugin. Most recent disclosed Dec 16, 2025.

1 critical 5 medium

Running Stylish Price List on your site? Check whether your installed version is affected.

Scan your site free

Stylish Price List &#8211; Price Table Builder &amp; QR Code Restaurant Menu [stylish-price-list] <= 7.2.2 (unfixed)

unknown

[en] Missing Authorization vulnerability in Design Stylish Price List stylish-price-list allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stylish Price List: from n/a through <= 7.2.2.

Affected:
up to 7.2.2
Fix:
No patched version reported
Disclosed:
Dec 16, 2025

CVE-2025-66122 on NVD →

Stylish Price List <= 7.2.2 - Missing Authorization

medium

The Stylish Price List plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 7.2.2. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 7.2.2
Fixed in:
7.2.3
Disclosed:
Nov 30, 2025

CVE-2025-66122 on NVD →

Stylish Price List &#8211; Price Table Builder &amp; QR Code Restaurant Menu [stylish-price-list] < 7.1.12

unknown

[en] The Stylish Price List WordPress plugin before 7.1.12 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 7.1.12
Fixed in:
7.1.12
Disclosed:
Mar 25, 2025

CVE-2024-10472 on NVD →

Stylish Price List <= 7.1.11 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Stylish Price List – Price Table Builder & QR Code Restaurant Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 7.1.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with ad...

CVSS:
4.4
Affected:
up to 7.1.11
Fixed in:
7.1.12
Disclosed:
Mar 3, 2025

CVE-2024-10472 on NVD →

Stylish Price List <= 7.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Stylish Price List – Price Table Builder & QR Code Restaurant Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 7.1.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level acce...

CVSS:
6.4
Affected:
up to 7.1.7
Fixed in:
7.1.8
Disclosed:
Sep 13, 2024

CVE-2024-7758 on NVD →

Stylish Price List &#8211; Price Table Builder &amp; QR Code Restaurant Menu [stylish-price-list] < 7.0.18

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Designful Stylish Price List – Price Table Builder & QR Code Restaurant Menu.This issue affects Stylish Price List – Price Table Builder & QR Code Restaurant Menu: from n/a through 7.0.17.

Affected:
up to 7.0.18
Fixed in:
7.0.18
Disclosed:
Jan 5, 2024

CVE-2023-51673 on NVD →

Stylish Price List <= 7.0.17 - Missing Authorization

medium

The Stylish Price List plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on multiple functions in versions up to, and including, 7.0.17. This makes it possible for authenticated attackers, with contributor-level access and above, to duplicate and delete p...

CVSS:
5.4
Affected:
up to 7.0.17
Fixed in:
7.0.18
Disclosed:
Dec 27, 2023

CVE-2023-51673 on NVD →

Stylish Price List &#8211; Price Table Builder &amp; QR Code Restaurant Menu [stylish-price-list] < 6.9.1

unknown

[en] The Stylish Price List WordPress plugin before 6.9.0 does not perform capability checks in its spl_upload_ser_img AJAX action (available to both unauthenticated and authenticated users), which could allow unauthenticated users to upload images.

Affected:
up to 6.9.1
Fixed in:
6.9.1
Disclosed:
Nov 1, 2021

CVE-2021-24757 on NVD →

Stylish Price List &#8211; Price Table Builder &amp; QR Code Restaurant Menu [stylish-price-list] < 6.9.1

unknown

[en] The Stylish Price List WordPress plugin before 6.9.1 does not perform capability checks in its spl_upload_ser_img AJAX action (available to authenticated users), which could allow any authenticated users, such as subscriber, to upload arbitrary images.

Affected:
up to 6.9.1
Fixed in:
6.9.1
Disclosed:
Nov 1, 2021

CVE-2021-24770 on NVD →

Stylish Price List < 6.9.0 - Arbitrary Image Upload

critical

The Stylish Price List WordPress plugin before 6.9.0 does not perform capability checks in its spl_upload_ser_img AJAX action (available to both unauthenticated and authenticated users), which could allow unauthenticated users to upload images.

CVSS:
9.8
Affected:
up to 6.9.0
Fixed in:
6.9.0
Disclosed:
Sep 29, 2021

CVE-2021-24757 on NVD →

Stylish Price List <= 6.9.0 - Missing Authorization

medium

The Stylish Price List WordPress plugin before 6.9.1 does not perform capability checks in its spl_upload_ser_img AJAX action (available to authenticated users), which could allow any authenticated users, such as subscriber, to upload arbitrary images.

CVSS:
6.5
Affected:
up to 6.9.0
Fixed in:
6.9.1
Disclosed:
Sep 29, 2021

CVE-2021-24770 on NVD →

Stylish Price List &#8211; Price Table Builder &amp; QR Code Restaurant Menu [stylish-price-list] < 7.1.8

unknown
Affected:
up to 7.1.8
Fixed in:
7.1.8

CVE-2024-7758 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database