Vulnerabilities > Wpdevart > Pricing Table Builder
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-06-05 | CVE-2023-0900 | Unspecified vulnerability in Wpdevart Pricing Table Builder 1.1.5/1.1.6 The Pricing Table Builder WordPress plugin through 1.1.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high-privilege users such as admins. | 7.2 |
2022-03-21 | CVE-2022-0640 | Cross-site Scripting vulnerability in Wpdevart Pricing Table Builder The Pricing Table Builder WordPress plugin before 1.1.5 does not sanitize and escape the postid parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting. | 4.3 |