Pricing Table by Supsystic <= 1.8.1 - Missing Authorization on AJAX Actions

2020-02-25 00:00
Chloe Chamberland

Strategic Overview

Status
Patched in 1.8.2
Affected Version<= 1.8.1
CVSS7.3High
CVECVE-2020-9392
View all Pricing Table by Supsystic vulnerabilities

Vulnerability Overview

An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. Because there is no permission check on the ImportJSONTable, createFromTpl, and getJSONExportTable endpoints, unauthenticated users can retrieve pricing table information, create new tables, or import/modify a table.

Technical Analysis

REMEDIATION: Update to version 1.8.2, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C