ARPrice Lite < 3.6.1 - Unauthenticated SQLi
45Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 13%
from disclosure to weapon
Published on NVDMay 16
VulnCheck+547d
exploitation probability
13%top 4% of all CVEs
observed exploitation
yesVulnCheck
The Pricing Table WordPress plugin before 3.6.1 fails to properly sanitize and escape user supplied POST data before it is being interpolated in an SQL statement and then executed via an AJAX action available to unauthenticated users
Affected products
Unknown · Pricing Table Plugin