CVE-2021-36896: WordPress Pricing Table plugin <= 1.5.2 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability
Published Apr 11, 2022
·Updated
Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Pricing Table (WordPress plugin) versions <= 1.5.2
Affected Software
1 affected component
W3eden Pricing Table Wordpress<=1.5.2
Event History
Apr 11, 2022
CVE Published
via MITRE·07:36 PM
Data Sourced
via MITRE·07:36 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2021-36896.
2
What is the severity of CVE-2021-36896?
The severity of CVE-2021-36896 is medium with a severity value of 4.8.
3
Which software versions are affected by CVE-2021-36896?
Pricing Table plugin versions up to and including 1.5.2 are affected by CVE-2021-36896.
4
What is the CWE ID for this vulnerability?
The CWE ID for CVE-2021-36896 is CWE-79.
5
How do I fix CVE-2021-36896?
To fix CVE-2021-36896, you should update Pricing Table plugin to a version higher than 1.5.2.