WP Pricing Table - Reflected XSS
CVE-2024-13628
Verified
Description
WP Pricing Table WordPress plugin <= 1.1 contains a reflected cross-site scripting caused by unsanitized parameter output, letting attackers execute scripts in the context of high privilege users, exploit requires attacker to craft malicious URL.
Severity
Medium
CVSS Score
6.1
Exploit Probability
1%
Published Date
February 7, 2026
Template Author
sourabh-sahu
CVE-2024-13628.yaml
6.1Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVE ID:
cve-2024-13628
CWE ID:
cwe-79
Remediation Steps
Update to the latest version of WP Pricing Table plugin that addresses the vulnerability or apply security patches.