CVE-2023-4810

The Responsive Pricing Table WordPress plugin before 5.1.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
References
Link Resource
https://portswigger.net/web-security/cross-site-scripting/stored Technical Description Third Party Advisory
https://wpscan.com/vulnerability/dfde5436-dd5c-4c70-a9c2-3cb85cc99c0a Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:wpdarko:responsive_pricing_table:*:*:*:*:*:wordpress:*:*

History

14 Nov 2023, 15:34

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.8
CPE cpe:2.3:a:wpdarko:responsive_pricing_table:*:*:*:*:*:wordpress:*:*
CWE CWE-79
First Time Wpdarko responsive Pricing Table
Wpdarko
References (MISC) https://portswigger.net/web-security/cross-site-scripting/stored - (MISC) https://portswigger.net/web-security/cross-site-scripting/stored - Technical Description, Third Party Advisory
References (MISC) https://wpscan.com/vulnerability/dfde5436-dd5c-4c70-a9c2-3cb85cc99c0a - (MISC) https://wpscan.com/vulnerability/dfde5436-dd5c-4c70-a9c2-3cb85cc99c0a - Exploit, Third Party Advisory

07 Nov 2023, 12:14

Type Values Removed Values Added
CWE CWE-79

06 Nov 2023, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-06 21:15

Updated : 2024-02-28 20:33


NVD link : CVE-2023-4810

Mitre link : CVE-2023-4810

CVE.ORG link : CVE-2023-4810


JSON object : View

Products Affected

wpdarko

  • responsive_pricing_table
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')