CVE-2026-94115: WordPress Easy Pricing Tables plugin <= 4.1.2 - SQL Injection vulnerability
Published Sep 30, 2026
·Updated
Contributor SQL Injection in Easy Pricing Tables <= 4.1.2 versions.
Affected Software
1 affected component
WordPress Easy Pricing Tables<=4.1.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Easy Pricing Tables pluginto a version that resolves this vulnerability.Fixed in 4.1.3
Event History
Sep 30, 2026
CVE Published
via MITRE·12:27 PM
Data Sourced
via MITRE·12:27 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs Contributor-level access to a WordPress site running an affected Easy Pricing Tables version. The attack can be performed remotely and does not require user interaction.
2
What is the potential impact?
Successful exploitation may allow SQL injection, with high confidentiality impact and a low availability impact. The scope is changed, meaning the vulnerable component could affect resources beyond its own security authority.
3
Which plugin versions are affected?
Easy Pricing Tables versions 4.1.2 and earlier are affected.