← Back

CVE-2020-9392

nvd nist
Published: Mar 23, 2020Modified: Nov 21, 2024

JSON object

Loading...
7.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Exploitability: 3.9 / Impact: 3.4
Source: NVD

Description

An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. Because there is no permission check on the ImportJSONTable, createFromTpl, and getJSONExportTable endpoints, unauthenticated users can retrieve pricing table information, create new tables, or import/modify a table.

Affected (1)

1 product
Pricing Table By Supsystic
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.8.2

Timeline

No history available yet.