CVE-2023-2496

HIGH

Go Pricing - WordPress Responsive Pricing Tables <= 3.3.19 - Arbitrary File Upload

Title source: llm
STIX 2.1

Description

The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to unauthorized arbitrary file uploads due to an improper capability check on the 'validate_upload' function in versions up to, and including, 3.3.19. This makes it possible for authenticated attackers with a role that the administrator previously granted access to the plugin to upload arbitrary files on the affected site's server which may make remote code execution possible.

Scores

CVSS v3 7.1
EPSS 0.0079
EPSS Percentile 51.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-285
Status published
Products (2)
Granth/Go Pricing - WordPress Responsive Pricing Tables < 3.3.19
granthweb/go_pricing < 3.3.19
Published May 24, 2023
Tracked Since Feb 18, 2026