First published: Mon Jun 05 2023(Updated: )
The Pricing Table Builder WordPress plugin through 1.1.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high-privilege users such as admins.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wpdevart Pricing Table Builder | <=1.1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-0900 is a high-severity SQL injection vulnerability in the Pricing Table Builder WordPress plugin through version 1.1.6.
Users of the Pricing Table Builder WordPress plugin version 1.1.6 or earlier are affected by CVE-2023-0900.
CVE-2023-0900 occurs due to the plugin's failure to properly sanitize and escape a parameter before using it in a SQL statement.
CVE-2023-0900 has a severity rating of high, with a severity value of 7.2.
To fix CVE-2023-0900, users should update to a version of the Pricing Table Builder WordPress plugin that has addressed the SQL injection vulnerability.