Extension WordPress
Vulnérabilités Pricing Table by Supsystic
Cette page rassemble les failles publiées pour Pricing Table by Supsystic, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Pricing Table by Supsystic
6 fiches
Pricing Table by Supsystic <= 1.9.12 – Authenticated (Admin+) Content Injection
The Pricing Table by Supsystic plugin for WordPress is vulnerable to content injection in all versions up to, and including, 1.9.12. This makes it possible for authenticated attackers, with admin-level access and above, to inject arbitrary content. This…
*-1.9.12
1.9.13
22/04/2024
Pricing Table by Supsystic <= 1.9.4 – Reflected Cross-Site Scripting
The Pricing Table by Supsystic WordPress plugin before 1.9.5 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting
*-1.9.4
1.9.5
09/04/2022
Pricing Table by Supsystic <= 1.8.8 – Boolean-Based Blind SQL Injections
The Pricing Table by Supsystic plugin for WordPress is vulnerable to boolean-based blind SQL Injection via the ‘sidx’ parameter in versions up to, and including, 1.8.8 due to insufficient escaping on the user-supplied parameter and lack of sufficient…
*-1.8.8
1.8.9
08/02/2021
Pricing Table by Supsystic <= 1.8.1 – Missing Authorization on AJAX Actions
An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. Because there is no permission check on the ImportJSONTable, createFromTpl, and getJSONExportTable endpoints, unauthenticated users can retrieve pricing table information, create new tables, or import/modify a…
*-1.8.1
1.8.2
25/02/2020
Pricing Table by Supsystic <= 1.8.1 – Unauthenticated Stored Cross-Site Scripting
An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows XSS.
*-1.8.1
1.8.2
25/02/2020
Pricing Table by Supsystic <= 1.8.1 – Cross-Site Request Forgery to Cross-Site Scripting and Setting Changes
An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows CSRF.
*-1.8.1
1.8.2
25/02/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.