Record summary

CVE-2022-1904 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The Pricing Tables WordPress Plugin WordPress plugin before 3.2.1 does not sanitise and escape parameter before outputting it back in a page available to any user (both authenticated and unauthenticated) when a specific setting is enabled, leading to a Reflected Cross-Site Scripting

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Pricing Tables WordPress Plugin – Easy Pricing Tables

CVE List3.2.1 to < 3.2.1affected

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Easy Pricing Tables <3.2.1 - Cross-Site ScriptingCVSS 6.1

WordPress Easy Pricing Tables plugin before 3.2.1 contains a reflected cross-site scripting vulnerability. It does not sanitize and escape a parameter before reflecting it back in a page available to any user both authenticated and unauthenticated when a specific setting is enabled.

Impact

Successful exploitation of this vulnerability could lead to cross-site scripting (XSS) attacks, allowing an attacker to execute malicious scripts on the victim's browser.

Remediation

Update to the latest version of WordPress Easy Pricing Tables plugin (3.2.1) to mitigate the vulnerability.

WeaknessesCWE-79
AuthorsAkincibor
Template tagscvecve2022wpwordpresswpscanwp-pluginxssfatcatappsvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:fatcatapps:easy_pricing_tables:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2