High severity7.3NVD Advisory· Published Mar 23, 2020· Updated Jun 17, 2026
CVE-2020-9392
CVE-2020-9392
Description
An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. Because there is no permission check on the ImportJSONTable, createFromTpl, and getJSONExportTable endpoints, unauthenticated users can retrieve pricing table information, create new tables, or import/modify a table.
Affected products
3- cpe:2.3:a:supsystic:pricing_table_by_supsystic:*:*:*:*:*:wordpress:*:*Range: <1.8.2
- WordPress/pricing-table-by-supsystic plugindescription
- Range: <1.8.2
Patches
Vulnerability mechanics
References
1- www.wordfence.com/blog/2020/02/multiple-vulnerabilities-patched-in-pricing-table-by-supsystic-plugin/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.