S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-0867 Scanner

Detects 'SQL Injection (SQLi)' vulnerability in Pricing Table plugin for WordPress affects v. before 3.6.1.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.6k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0867
9.8
CVSS

The Pricing Table WordPress plugin before 3.6.1 fails to properly sanitize and escape user supplied POST data before it is being interpolated in an SQL statement and then executed via an AJAX action available to unauthenticated users

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Pricing Table Plugin
AFFECTED< 3.6.1SAFE ✓≥ 3.6.1
Updated Aug 22, 2026View on NVD →
Detail

The Pricing Table WordPress plugin is a popular tool used to create pricing tables for websites. This plugin allows website owners to easily display their products or services with multiple pricing options in an organized manner. The plugin offers a variety of features that can help businesses increase their sales and attract more customers. With its user-friendly interface and customization options, the Pricing Table plugin is a must-have for WordPress users who want to showcase their offerings in an appealing way.

However, the plugin suffers from a critical vulnerability, detected as CVE-2022-0867. The vulnerability arises from the plugin's failure to properly sanitize and escape user-supplied POST data. This leaves the product exposed to SQL injection attacks, which can be used to execute arbitrary code on the server, potentially leading to a complete compromise of the website.

If the vulnerability is successfully exploited, hackers can gain access to sensitive data, such as customer information and payment details. They can use the vulnerability to inject malicious code into the server, which can lead to serious consequences, including the exposure of confidential data and damage to a business's reputation.

Thanks to the pro features of the s4e.io platform, readers of this article can quickly and easily learn about vulnerabilities in their digital assets. The platform provides comprehensive vulnerability scanning and testing that identifies all potential security issues. This service is a must-have for any website owner who wants to ensure the security of their online presence. Don't risk your business and website security, get the protection the s4e.io platform provides.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website owners who use the Pricing Table plugin should follow the following precautions:

  • Update the plugin to the latest version (3.6.1), which includes a patch for the vulnerability.
  • Regularly check for updates to the plugin and other software on the website.
  • Limit the use of plugins to essential ones only.
  • Keep the website's software and operating system up to date.
  • Implement a web application firewall (WAF) to provide additional security against malicious attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.