CVE-2022-1904
Easy Pricing Tables < 3.2.1 - Reflected Cross-Site-Scripting
Record summary
CVE-2022-1904 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The Pricing Tables WordPress Plugin WordPress plugin before 3.2.1 does not sanitise and escape parameter before outputting it back in a page available to any user (both authenticated and unauthenticated) when a specific setting is enabled, leading to a Reflected Cross-Site Scripting
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Pricing Tables WordPress Plugin – Easy Pricing Tables | CVE List | 3.2.1 to < 3.2.1 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress Easy Pricing Tables <3.2.1 - Cross-Site ScriptingCVSS 6.1
WordPress Easy Pricing Tables plugin before 3.2.1 contains a reflected cross-site scripting vulnerability. It does not sanitize and escape a parameter before reflecting it back in a page available to any user both authenticated and unauthenticated when a specific setting is enabled.
Impact
Successful exploitation of this vulnerability could lead to cross-site scripting (XSS) attacks, allowing an attacker to execute malicious scripts on the victim's browser.
Remediation
Update to the latest version of WordPress Easy Pricing Tables plugin (3.2.1) to mitigate the vulnerability.
Source: ProjectDiscovery