CVE-2022-0640: AP Pricing Tables Lite < 1.1.5 - Reflected Cross-Site Scripting
Published Mar 21, 2022
·Updated
The Pricing Table Builder WordPress plugin before 1.1.5 does not sanitize and escape the postid parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
Affected Software
1 affected component
WpDevArt Pricing Table Builder Wordpress<1.1.5
Event History
Mar 21, 2022
CVE Published
via MITRE·06:55 PM
Data Sourced
via MITRE·06:55 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for the Pricing Table Builder WordPress plugin?
The vulnerability ID for the Pricing Table Builder WordPress plugin is CVE-2022-0640.
2
What is the severity level of CVE-2022-0640?
The severity level of CVE-2022-0640 is medium.
3
What is the affected software for CVE-2022-0640?
The affected software for CVE-2022-0640 is the Pricing Table Builder WordPress plugin before version 1.1.5.
4
What is the CWE category for CVE-2022-0640?
The CWE category for CVE-2022-0640 is CWE-79.
5
How can I fix the CVE-2022-0640 vulnerability in the Pricing Table Builder WordPress plugin?
To fix the CVE-2022-0640 vulnerability in the Pricing Table Builder WordPress plugin, update to version 1.1.5 or later.