CVE-2023-0900: AP Pricing Tables Lite <= 1.1.6 - Admin+ SQLi
The Pricing Table Builder WordPress plugin through 1.1.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high-privilege users such as admins.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-0900?
CVE-2023-0900 is a high-severity SQL injection vulnerability in the Pricing Table Builder WordPress plugin through version 1.1.6.
Who is affected by CVE-2023-0900?
Users of the Pricing Table Builder WordPress plugin version 1.1.6 or earlier are affected by CVE-2023-0900.
How does CVE-2023-0900 occur?
CVE-2023-0900 occurs due to the plugin's failure to properly sanitize and escape a parameter before using it in a SQL statement.
What is the severity of CVE-2023-0900?
CVE-2023-0900 has a severity rating of high, with a severity value of 7.2.
How can CVE-2023-0900 be fixed?
To fix CVE-2023-0900, users should update to a version of the Pricing Table Builder WordPress plugin that has addressed the SQL injection vulnerability.