← back
CVE-2022-0867observed exploitationCWE-89

ARPrice Lite < 3.6.1 - Unauthenticated SQLi

45Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 13%
from disclosure to weapon
Published on NVDMay 16
VulnCheck+547d
exploitation probability
13%top 4% of all CVEs
observed exploitation
yesVulnCheck
The Pricing Table WordPress plugin before 3.6.1 fails to properly sanitize and escape user supplied POST data before it is being interpolated in an SQL statement and then executed via an AJAX action available to unauthenticated users