CVE-2024-32790: WordPress Pricing Table by Supsystic plugin <= 1.9.12 - Content Injection vulnerability
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Supsystic Pricing Table by Supsystic allows Code Injection.This issue affects Pricing Table by Supsystic: from n/a through 1.9.12.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32790?
CVE-2024-32790 is a medium-severity vulnerability that allows for code injection via improper neutralization of script-related HTML tags.
How do I fix CVE-2024-32790?
To fix CVE-2024-32790, update the Supsystic Pricing Table plugin to the latest version released after 1.9.12.
What types of attacks can CVE-2024-32790 facilitate?
CVE-2024-32790 can facilitate cross-site scripting (XSS) attacks, potentially allowing attackers to execute arbitrary scripts in the context of the user's session.
Which versions of Supsystic Pricing Table are affected by CVE-2024-32790?
CVE-2024-32790 affects all versions of Supsystic Pricing Table up to and including version 1.9.12.
Who is the vendor responsible for CVE-2024-32790?
The vendor responsible for CVE-2024-32790 is Supsystic, the developer of the Pricing Table plugin.