Impact
The Responsive Pricing Table WordPress plugin allows authenticated users with Contributor or higher access to inject arbitrary scripts through the 'table_currency' field. Once injected, the script runs on any page that displays the affected table, providing attackers with the ability to deface content, steal user data, or perform further attacks in the victim’s web session. The flaw is a classic stored XSS identified as CWE‑80, which compromises confidentiality, integrity, and availability of the affected WordPress site.
Affected Systems
The vulnerability exists in all releases of the Responsive Pricing Table plugin up to and including version 5.1.12. It affects all WordPress installations that use this plugin and where a user holds Contributor level or higher permissions.
Risk and Exploitability
The CVSS score of 6.4 reflects a moderate severity, and the EPSS score of less than 1 % indicates low exploitation probability in the general web environment. The flaw is not listed in the CISA KEV catalog. Attackers would typically need to authenticate and have Contributor access; from that position they can craft a malicious 'table_currency' value, inject it into a table, and subsequently have it rendered to any visitor who views the affected page.
OpenCVE Enrichment