S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-1904 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in Easy Pricing Tables plugin for WordPress affects v. efore 3.2.1.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.4k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-1904
6.1
CVSS

The Pricing Tables WordPress Plugin WordPress plugin before 3.2.1 does not sanitise and escape parameter before outputting it back in a page available to any user (both authenticated and unauthenticated) when a specific setting is enabled, leading to a Reflected Cross-Site Scripting

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Pricing Tables WordPress Plugin – Easy Pricing Tables
AFFECTED< 3.2.1SAFE ✓≥ 3.2.1
Updated Aug 22, 2026View on NVD →
Detail

The Easy Pricing Tables plugin for WordPress is a popular tool used by website owners to create and display responsive pricing tables on their websites. The plugin offers a range of customization options, including different designs, layouts and pricing plans. With the Easy Pricing Tables plugin, website owners can easily create professional-looking pricing tables that help to improve the user experience and conversions on their website.

However, the plugin has recently been identified to have a vulnerability that exposes users to Reflected Cross-Site Scripting. This vulnerability, which has been tagged as CVE-2022-1904, is attributed to the plugin’s failure to sanitize and escape parameters before outputting them in a page. As such, any user, whether authorized or not, can exploit this vulnerability by injecting malicious code into the plugin’s parameters, leading to the execution of unwanted scripts on a user’s browser.

The exploitation of this vulnerability can have severe consequences for websites that use the Easy Pricing Tables plugin. Hackers can use this opportunity to steal sensitive information, such as users’ login credentials; execute phishing attacks; or even take over a website entirely. The vulnerability can also result in the installation of malware on users’ devices, leading to additional security risks and damage.

In conclusion, website owners need to be aware of the potential risks posed by vulnerabilities in their digital assets. Fortunately, platforms such as s4e.io offer pro features that can be used to quickly identify and mitigate such vulnerabilities. By using these features, website owners can ensure that their digital assets remain secure and free from attacks.

 

REFERENCES

Solution Advice

To protect websites from this vulnerability, the following precautions can be taken:

  • Update the Easy Pricing Tables plugin to the latest version, which includes a fix for the vulnerability.
  • Regularly monitor website logs to detect any attempts at exploiting the vulnerability.
  • Use web application firewalls (WAFs) to prevent or mitigate attacks.
  • Limit user permissions to prevent unauthorized access to the website.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.