7.5
CVSSv2

CVE-2020-9392

Published: 23/03/2020 Updated: 25/03/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 7.3 | Impact Score: 3.4 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in the pricing-table-by-supsystic plugin prior to 1.8.2 for WordPress. Because there is no permission check on the ImportJSONTable, createFromTpl, and getJSONExportTable endpoints, unauthenticated users can retrieve pricing table information, create new tables, or import/modify a table.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

supsystic pricing table by supsystic