Impact
A Cross‑Site Request Forgery flaw in the wpdevart Pricing Table builder plugin lets an attacker store arbitrary JavaScript in a pricing table. When the table is loaded on any visitor or administrator page, the injected script executes, enabling credential theft, session hijacking, or defacement of site content.
Affected Systems
The wpdevart Pricing Table builder plugin for WordPress, in any release from the earliest available version through 1.5.3, is affected. Site owners should verify whether the installed plugin falls within this range.
Risk and Exploitability
The CVSS score of 7.1 rates this vulnerability as high impact, while an EPSS score of less than 1 % indicates a low but non‑zero likelihood of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Because the attack requires submission of a malicious request through the plugin’s form, the likely attack vector involves an authenticated user session that can be lured to submit the payload; this inference comes from the CSRF nature of the defect and the need to inject content into a stored table. Any successful exploitation would allow a remote attacker to execute code in the browser context of all site visitors.
OpenCVE Enrichment