S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Mar 8, 2024

CVE-2023-0900 Scanner

CVE-2023-0900 scanner - SQL Injection vulnerability in AP Pricing Tables Lite

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.8k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-0900
7.2
CVSShigh
Exploitable remotely over the internet · requires high privileges.

The Pricing Table Builder WordPress plugin through 1.1.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high-privilege users such as admins.

Attack Vector
Network
Privileges Req.
High
User Interaction
None
Affected
Pricing Table Builder
0
Updated Aug 22, 2026View on NVD →
Detail

AP Pricing Tables Lite is a WordPress plugin developed by WPDevArt, designed to allow WordPress site administrators to easily create and manage pricing tables. This plugin is widely used by businesses and individual site owners to display pricing information for products, services, or packages in an organized and aesthetically pleasing manner. Its user-friendly interface and customizable design options make it a popular choice for enhancing the user experience and providing clear pricing information on websites.

The vulnerability detected in AP Pricing Tables Lite up to version 1.1.6 is a SQL Injection (SQLi), a critical security issue that allows attackers to execute arbitrary SQL commands through the plugin. This flaw is specifically exploitable by users with administrative privileges, such as site admins, due to improper sanitization and escaping of parameters before incorporating them into SQL queries.

This SQL Injection vulnerability arises from the plugin's mishandling of certain parameters that are used in SQL statements without proper validation or sanitation. As a result, an attacker with administrative access can manipulate SQL queries to perform actions such as accessing sensitive data, modifying database contents, or even dropping tables. The issue is triggered via specific actions within the plugin's administrative interface, highlighting the importance of strict input validation and parameter sanitization in web applications.

Exploiting this vulnerability could lead to unauthorized access to sensitive information stored in the WordPress site's database, including user credentials, personal data, and website configuration details. Additionally, attackers could manipulate or delete data, leading to website dysfunction, loss of data integrity, and potentially taking complete control of the affected site.

By becoming a member of the S4E platform, you gain access to our state-of-the-art Cyber Threat Exposure Management service, which includes the detection of vulnerabilities like the SQL Injection in AP Pricing Tables Lite. Our platform uses advanced scanning techniques and proprietary software to identify and report security weaknesses, providing you with the knowledge and tools necessary to secure your digital assets effectively. Join us to enhance your cybersecurity posture and protect your website from potential threats.

 

References

Solution Advice
  1. Immediately update the AP Pricing Tables Lite plugin to the latest version available that addresses this SQL Injection vulnerability.
  2. Ensure all WordPress plugins and themes are regularly updated to their latest versions.
  3. Use strong, unique passwords for all user accounts, especially for administrative roles.
  4. Limit the number of users with administrative privileges to minimize the risk of exploitation.
  5. Implement a web application firewall (WAF) to detect and block SQL Injection and other common web application attacks.
  6. Conduct regular security audits and vulnerability assessments to identify and remediate potential security issues.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.