The Pricing Table WordPress plugin before 3.6.1 fails to properly sanitize and escape user supplied POST data before it is being interpolated in an SQL statement and then executed via an AJAX action available to unauthenticated users
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2022-05-16T14:30:29

Updated: 2022-05-16T14:30:29

Reserved: 2022-03-04T00:00:00


Link: CVE-2022-0867

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-05-16T15:15:08.657

Modified: 2022-05-24T20:26:20.100


Link: CVE-2022-0867

JSON object: View

cve-icon Redhat Information

No data.

CWE