cleantalk
Vulnerabilities and Security Researches

Pricing Table by Supsystic, CVE-2020-9392

CVE, Research URL

CVE-2020-9392

Published on
Mar 23, 2020
Research Description
An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. Because there is no permission check on the ImportJSONTable, createFromTpl, and getJSONExportTable endpoints, unauthenticated users can retrieve pricing table information, create new tables, or import/modify a table.
Affected versions
max 1.8.2.
Status
vulnerable