Lucene search

K
wpvulndbRan CraneWPVDB-ID:F8405E06-9CF3-4ACB-AEBB-E80FB402DAA9
HistoryFeb 28, 2022 - 12:00 a.m.

AP Pricing Tables Lite < 1.1.5 - Reflected Cross-Site Scripting

2022-02-2800:00:00
Ran Crane
wpscan.com
16

0.001 Low

EPSS

Percentile

30.2%

The plugin does not sanitize and escape the postid parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

PoC

https://example.com/wp-admin/admin.php?page=ap-pricing-tables-lite-add-new&amp;postid;=1’>

CPENameOperatorVersion
ap-pricing-tables-litelt1.1.5

0.001 Low

EPSS

Percentile

30.2%

Related for WPVDB-ID:F8405E06-9CF3-4ACB-AEBB-E80FB402DAA9