Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3
Critical0
High0
Medium3
Reset
Showing 1-3 of 3 records
Threat Entry Updated 2025-02-21

CVE-2024-13582 - Pricing Tables Plugin

The Simple Pricing Tables For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wdo_simple_pricing_table_free' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Pricing Tables

CVE-2024-13582

MEDIUM CVSS 6.4 2025-02-18
Threat Entry Updated 2024-11-21

CVE-2022-1904 - Pricing Tables Plugin

The Pricing Tables WordPress Plugin WordPress plugin before 3.2.1 does not sanitise and escape parameter before outputting it back in a page available to any user (both authenticated and unauthenticated) when a specific setting is enabled, leading to a Reflected Cross-Site Scripting

PLUGIN Pricing Tables

CVE-2022-1904

MEDIUM CVSS 6.1 2022-06-27
Threat Entry Updated 2024-11-21

CVE-2021-25098 - Pricing Tables Plugin

The Pricing Tables WordPress Plugin WordPress plugin before 3.1.3 does not verify the CSRF nonce when removing posts, allowing attackers to make a logged in admin remove arbitrary posts from the blog via a CSRF attack, which will be put in the trash

PLUGIN Pricing Tables

CVE-2021-25098

MEDIUM CVSS 6.5 2022-03-07
Scroll to top