CVE Vulnerabilities

CVE-2022-4654

Published: Jan 30, 2023 | Modified: Mar 28, 2025
CVSS 3.x
5.4
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Pricing Tables WordPress Plugin WordPress plugin before 3.2.3 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

Affected Software

NameVendorStart VersionEnd Version
Pricing_tablesFatcatapps*3.2.3 (excluding)

References