CVE-2021-46782: Pricing Table by Supsystic < 1.9.5 - Reflected Cross-Site Scripting
The Pricing Table by Supsystic WordPress plugin before 1.9.5 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-46782?
CVE-2021-46782 is a vulnerability in the Pricing Table by Supsystic WordPress plugin that allows for Reflected Cross-Site Scripting.
How does CVE-2021-46782 impact the affected software?
CVE-2021-46782 impacts the Pricing Table by Supsystic WordPress plugin before version 1.9.5 by allowing an attacker to execute malicious scripts in the admin dashboard via a crafted tab parameter.
What is the severity of CVE-2021-46782?
CVE-2021-46782 has a severity rating of 6.1 (Medium).
How can CVE-2021-46782 be fixed?
To fix CVE-2021-46782, users should update the Pricing Table by Supsystic WordPress plugin to version 1.9.5 or later.
What is the CWE classification for CVE-2021-46782?
CVE-2021-46782 is classified under CWE-79 (Cross-Site Scripting).