📦

pricing_table_builder

Vendor: wpdevart

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 0 Remote Access
Total CVEs 2 Total Indexed
Avg. EPSS 2.04% Exploit Prob.
Latest CVE CVE-2023-0900 Jun 05

Security Vulnerability Index

Page 1 / 1
7.2 CVSS

The Pricing Table Builder WordPress plugin through 1.1.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high-privilege users such as admins.

EPSS: 3.23%
6.1 CVSS

The Pricing Table Builder WordPress plugin before 1.1.5 does not sanitize and escape the postid parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

EPSS: 0.85%