ZeroHour

CVE-2022-0867

PoC
CVSS 3.1
9.8 critical
EPSS
13%p96
Published
()
Modified
Description

The Pricing Table WordPress plugin before 3.6.1 fails to properly sanitize and escape user supplied POST data before it is being interpolated in an SQL statement and then executed via an AJAX action available to unauthenticated users

Vendors
reputeinfosystems
Products
pricing table
Ecosystems
WordPress
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.