Impact
The Product Pricing Table by WooBeWoo plugin for WordPress is vulnerable to Cross‑Site Request Forgery due to missing or incorrect nonce validation on the updateLabel() and remove() functions. An attacker who can entice a site administrator into visiting a crafted link can inject arbitrary scripts into the site’s pages or delete pricing tables. The injected scripts execute with the privileges of the logged‑in administrator, potentially exposing sensitive data or compromising site functionality.
Affected Systems
All versions of the Product Pricing Table by WooBeWoo plugin up to and including 1.1.0, which are installed on WordPress sites.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.1, indicating moderate severity. Exploit probability data is unavailable and the vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. The likely attack vector is through social engineering; an attacker sends a forged request to an administrator who mistakenly triggers the vulnerable action, thereby achieving the stored XSS and pricing table deletion outcomes.
OpenCVE Enrichment