ZeroHour

CVE-2020-9392

PoC
CVSS 3.1
7.3 high
EPSS
2%p76
Published
()
Modified
Description

An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. Because there is no permission check on the ImportJSONTable, createFromTpl, and getJSONExportTable endpoints, unauthenticated users can retrieve pricing table information, create new tables, or import/modify a table.

Vendors
supsystic
Products
pricing table by supsystic
Ecosystems
WordPress
Weakness
CWE-276
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.