Vulnerabilities
Summary — last 7 days
New vulnerabilities2,623▼ 224 vs. last week
Critical / high1,384▲ 157 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)56▼ 472 vs. last week
48 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | High (8.5) | 0.26% | — | Fatcatapps Easy Pricing TablesAI | 9/30/2026 | 9/30/2026 | Contributor SQL Injection in Easy Pricing Tables <= 4.1.2 versions. | |
| Deferred | High (8.8) | 0.28% | — | Supsystic Pricing TableAI | 5/16/2026 | 9/29/2026 | Supsystic Pricing Table 1.8.7 contains an SQL injection vulnerability in the 'sidx' GET parameter that allows unauthenticated attackers to execute arbitrary SQL queries through the getListForTbl action. The plugin also contains stored cross-site scripting vulnerabilities in the 'Edit name' and 'Edit HTML' fields that… | |
| Deferred | Medium (6.1) | 0.36% | — | Pricing Tables FOR WPAI | 5/12/2026 | 6/17/2026 | The Pricing Tables for WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.1.0. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Deferred | Medium (6.1) | 0.13% | — | Woobewoo Product Pricing TableAI | 4/15/2026 | 6/17/2026 | The Product Pricing Table by WooBeWoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to missing or incorrect nonce validation on the updateLabel() and remove() functions. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Deferred | Medium (6.4) | 0.64% | — | Wpdarko Responsive Pricing TableAI | 1/7/2026 | 6/17/2026 | The Responsive Pricing Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'plan_icons' parameter in all versions up to, and including, 5.1.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above,… | |
| Deferred | Medium (6.4) | 0.26% | — | Wpdarko Responsive Pricing TableAI | 1/7/2026 | 9/30/2026 | The Responsive Pricing Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'table_currency' parameter in all versions up to, and including, 5.1.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access… | |
| Deferred | High (7.1) | 0.14% | — | Wpdevart Pricing Table BuilderAI | 10/27/2025 | 6/17/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wpdevart Pricing Table builder wpdevart-pricing-table allows Stored XSS.This issue affects Pricing Table builder: from n/a through <= 1.5.3. | |
| Deferred | High (7.5) | 0.67% | — | Pluginwale Easy Pricing Table WPAI | 9/22/2025 | 6/17/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Pluginwale Easy Pricing Table WP easy-pricing-table-wp allows PHP Local File Inclusion.This issue affects Easy Pricing Table WP: from n/a through <= 1.1.3. | |
| Deferred | High (7.1) | 0.24% | — | Quanticalabs Css3 Compare Pricing TablesAI | 7/16/2025 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuanticaLabs CSS3 Compare Pricing Tables for WordPress css3_web_pricing_tables_grids allows Reflected XSS.This issue affects CSS3 Compare Pricing Tables for WordPress: from n/a through <= 11.6. | |
| Deferred | High (7.1) | 0.21% | — | Quanticalabs Css3 Vertical WEB Pricing TablesAI | 6/27/2025 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuanticaLabs CSS3 Vertical Web Pricing Tables css3_vertical_web_pricing_tables allows Reflected XSS.This issue affects CSS3 Vertical Web Pricing Tables: from n/a through <= 1.9. | |
| Deferred | Medium (5.4) | 0.35% | — | Quanticalabs Css3 Compare Pricing TablesAI | 5/16/2025 | 6/17/2026 | Missing Authorization vulnerability in QuanticaLabs CSS3 Compare Pricing Tables for WordPress css3_web_pricing_tables_grids allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CSS3 Compare Pricing Tables for WordPress: from n/a through <= 11.6. | |
| Analyzed | Medium (5.4) | 0.21% | — | Pickplugins Pricing Table | 2/28/2025 | 6/17/2026 | The Pricing Table by PickPlugins plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button Link in all versions up to, and including, 1.12.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,… | |
| Analyzed | Medium (6.1) | 0.65% | — | Codecabin WP Pricing Table | 2/26/2025 | 6/17/2026 | The WP Pricing Table WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Deferred | High (7.1) | 0.24% | — | Totalsoft WOO Pricing TableAI | 2/23/2025 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in totalsoft WooCommerce Pricing – Product Pricing woo-pricing-table allows Stored XSS.This issue affects WooCommerce Pricing – Product Pricing: from n/a through <= 1.0.9. | |
| Analyzed | Medium (5.4) | 0.25% | — | Webdevocean Pricing Tables | 2/18/2025 | 6/17/2026 | The Simple Pricing Tables For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wdo_simple_pricing_table_free' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user… | |
| Deferred | Medium (5.3) | 0.64% | — | Realwebcare WRC Pricing TablesAI | 12/9/2024 | 6/17/2026 | Missing Authorization vulnerability in Realwebcare WRC Pricing Tables allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WRC Pricing Tables: from n/a through 2.3.7. | |
| Deferred | High (7.5) | 0.71% | — | Ibrahim Pricing Table Addon FOR ElementorAI | 11/28/2024 | 6/17/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Ibrahim Pricing table addon for elementor pricing-table-addon-for-elementor allows PHP Local File Inclusion.This issue affects Pricing table addon for elementor: from n/a through <= 1.0.0. | |
| Deferred | Medium (6.4) | 0.27% | — | WDO Pricing TablesAI | 11/27/2024 | 6/17/2026 | The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wdo_pricing_tables shortcode in all versions up to, and including, 1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This… | |
| Deferred | Medium (6.5) | 0.28% | — | Seothemes Simple Pricing TableAI | 11/19/2024 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in seothemes Simple Pricing Table simple-pricing-table allows Stored XSS.This issue affects Simple Pricing Table: from n/a through <= 1.0.0. | |
| Deferred | Medium (6.5) | 0.38% | — | Commonninja Pricer Ninja Pricing TablesAI | 11/19/2024 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Common Ninja Pricer Ninja pricer-ninja-pricing-tables allows Stored XSS.This issue affects Pricer Ninja: from n/a through <= 2.1.0. | |
| Deferred | Medium (6.5) | 0.24% | — | Offshorent Solutions PVT LTD OS Pricing TablesAI | 11/18/2024 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Offshorent Solutions Pvt Ltd OS Pricing Tables os-pricing-tables allows Stored XSS.This issue affects OS Pricing Tables: from n/a through <= 1.2. | |
| Analyzed | Medium (5.4) | 0.33% | — | Fatcatapps Easy Pricing Tables | 11/6/2024 | 6/17/2026 | The Pricing Tables WordPress Plugin – Easy Pricing Tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘fontFamily’ attribute in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Deferred | Medium (6.1) | 0.36% | — | Fatcatapps Easy Pricing TablesAI | 10/30/2024 | 6/17/2026 | The Pricing Tables WordPress Plugin – Easy Pricing Tables plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.2.5. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Deferred | Medium (5.4) | 0.27% | — | Pricing TableAI | 7/9/2024 | 6/17/2026 | The Pricing Table plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax() function in all versions up to, and including, 2.0.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unauthorized actions like… | |
| Deferred | Medium (5.3) | 0.20% | — | Pricing TableAI | 7/9/2024 | 6/17/2026 | The Pricing Table plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.1. This is due to missing or incorrect nonce validation on the ajax() function. This makes it possible for unauthenticated attackers to perform a variety of actions related to managing pricing… |