Vulnerabilities > Wpdevart > Pricing Table Builder

DATE CVE VULNERABILITY TITLE RISK
2023-06-05 CVE-2023-0900 Unspecified vulnerability in Wpdevart Pricing Table Builder 1.1.5/1.1.6
The Pricing Table Builder WordPress plugin through 1.1.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high-privilege users such as admins.
network
low complexity
wpdevart
7.2
2022-03-21 CVE-2022-0640 Cross-site Scripting vulnerability in Wpdevart Pricing Table Builder
The Pricing Table Builder WordPress plugin before 1.1.5 does not sanitize and escape the postid parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
network
wpdevart CWE-79
4.3