Vulnerabilities

Summary — last 7 days

New vulnerabilities2,623▼ 224 vs. last week
Critical / high1,384▲ 157 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)56▼ 472 vs. last week
–

48 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredHigh (8.5)0.26%—Fatcatapps Easy Pricing TablesAI9/30/20269/30/2026
Contributor SQL Injection in Easy Pricing Tables <= 4.1.2 versions.
DeferredHigh (8.8)0.28%—Supsystic Pricing TableAI5/16/20269/29/2026
Supsystic Pricing Table 1.8.7 contains an SQL injection vulnerability in the 'sidx' GET parameter that allows unauthenticated attackers to execute arbitrary SQL queries through the getListForTbl action. The plugin also contains stored cross-site scripting vulnerabilities in the 'Edit name' and 'Edit HTML' fields that…
DeferredMedium (6.1)0.36%—Pricing Tables FOR WPAI5/12/20266/17/2026
The Pricing Tables for WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.1.0. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
DeferredMedium (6.1)0.13%—Woobewoo Product Pricing TableAI4/15/20266/17/2026
The Product Pricing Table by WooBeWoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to missing or incorrect nonce validation on the updateLabel() and remove() functions. This makes it possible for unauthenticated attackers to inject arbitrary…
DeferredMedium (6.4)0.64%—Wpdarko Responsive Pricing TableAI1/7/20266/17/2026
The Responsive Pricing Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'plan_icons' parameter in all versions up to, and including, 5.1.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above,…
DeferredMedium (6.4)0.26%—Wpdarko Responsive Pricing TableAI1/7/20269/30/2026
The Responsive Pricing Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'table_currency' parameter in all versions up to, and including, 5.1.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access…
DeferredHigh (7.1)0.14%—Wpdevart Pricing Table BuilderAI10/27/20256/17/2026
Cross-Site Request Forgery (CSRF) vulnerability in wpdevart Pricing Table builder wpdevart-pricing-table allows Stored XSS.This issue affects Pricing Table builder: from n/a through <= 1.5.3.
DeferredHigh (7.5)0.67%—Pluginwale Easy Pricing Table WPAI9/22/20256/17/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Pluginwale Easy Pricing Table WP easy-pricing-table-wp allows PHP Local File Inclusion.This issue affects Easy Pricing Table WP: from n/a through <= 1.1.3.
DeferredHigh (7.1)0.24%—Quanticalabs Css3 Compare Pricing TablesAI7/16/20256/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuanticaLabs CSS3 Compare Pricing Tables for WordPress css3_web_pricing_tables_grids allows Reflected XSS.This issue affects CSS3 Compare Pricing Tables for WordPress: from n/a through <= 11.6.
DeferredHigh (7.1)0.21%—Quanticalabs Css3 Vertical WEB Pricing TablesAI6/27/20256/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuanticaLabs CSS3 Vertical Web Pricing Tables css3_vertical_web_pricing_tables allows Reflected XSS.This issue affects CSS3 Vertical Web Pricing Tables: from n/a through <= 1.9.
DeferredMedium (5.4)0.35%—Quanticalabs Css3 Compare Pricing TablesAI5/16/20256/17/2026
Missing Authorization vulnerability in QuanticaLabs CSS3 Compare Pricing Tables for WordPress css3_web_pricing_tables_grids allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CSS3 Compare Pricing Tables for WordPress: from n/a through <= 11.6.
AnalyzedMedium (5.4)0.21%—Pickplugins Pricing Table2/28/20256/17/2026
The Pricing Table by PickPlugins plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button Link in all versions up to, and including, 1.12.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,…
AnalyzedMedium (6.1)0.65%—Codecabin WP Pricing Table2/26/20256/17/2026
The WP Pricing Table WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
DeferredHigh (7.1)0.24%—Totalsoft WOO Pricing TableAI2/23/20256/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in totalsoft WooCommerce Pricing – Product Pricing woo-pricing-table allows Stored XSS.This issue affects WooCommerce Pricing – Product Pricing: from n/a through <= 1.0.9.
AnalyzedMedium (5.4)0.25%—Webdevocean Pricing Tables2/18/20256/17/2026
The Simple Pricing Tables For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wdo_simple_pricing_table_free' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user…
DeferredMedium (5.3)0.64%—Realwebcare WRC Pricing TablesAI12/9/20246/17/2026
Missing Authorization vulnerability in Realwebcare WRC Pricing Tables allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WRC Pricing Tables: from n/a through 2.3.7.
DeferredHigh (7.5)0.71%—Ibrahim Pricing Table Addon FOR ElementorAI11/28/20246/17/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Ibrahim Pricing table addon for elementor pricing-table-addon-for-elementor allows PHP Local File Inclusion.This issue affects Pricing table addon for elementor: from n/a through <= 1.0.0.
DeferredMedium (6.4)0.27%—WDO Pricing TablesAI11/27/20246/17/2026
The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wdo_pricing_tables shortcode in all versions up to, and including, 1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This…
DeferredMedium (6.5)0.28%—Seothemes Simple Pricing TableAI11/19/20246/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in seothemes Simple Pricing Table simple-pricing-table allows Stored XSS.This issue affects Simple Pricing Table: from n/a through <= 1.0.0.
DeferredMedium (6.5)0.38%—Commonninja Pricer Ninja Pricing TablesAI11/19/20246/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Common Ninja Pricer Ninja pricer-ninja-pricing-tables allows Stored XSS.This issue affects Pricer Ninja: from n/a through <= 2.1.0.
DeferredMedium (6.5)0.24%—Offshorent Solutions PVT LTD OS Pricing TablesAI11/18/20246/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Offshorent Solutions Pvt Ltd OS Pricing Tables os-pricing-tables allows Stored XSS.This issue affects OS Pricing Tables: from n/a through <= 1.2.
AnalyzedMedium (5.4)0.33%—Fatcatapps Easy Pricing Tables11/6/20246/17/2026
The Pricing Tables WordPress Plugin – Easy Pricing Tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘fontFamily’ attribute in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
DeferredMedium (6.1)0.36%—Fatcatapps Easy Pricing TablesAI10/30/20246/17/2026
The Pricing Tables WordPress Plugin – Easy Pricing Tables plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.2.5. This makes it possible for unauthenticated attackers to inject arbitrary…
DeferredMedium (5.4)0.27%—Pricing TableAI7/9/20246/17/2026
The Pricing Table plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax() function in all versions up to, and including, 2.0.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unauthorized actions like…
DeferredMedium (5.3)0.20%—Pricing TableAI7/9/20246/17/2026
The Pricing Table plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.1. This is due to missing or incorrect nonce validation on the ajax() function. This makes it possible for unauthenticated attackers to perform a variety of actions related to managing pricing…