What the vulnerability does
01Description
The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'process_postdata' function in versions up to, and including, 3.3.19. This makes it possible for authenticated attackers with a role that the administrator previously granted access to the plugin to modify access to the plugin when it should only be the administrator's privilege.
Explanation of Vulnerability in Simple Terms
02Summary
The Go Pricing plugin for WordPress does not properly check user permissions before allowing certain actions. A logged-in user with low privileges can perform unauthorized operations by visiting a specially crafted page, potentially modifying pricing data or other plugin settings. The vulnerability requires user interaction and has limited impact on confidentiality, integrity, and availability.
What an attacker can do
03Attacker Capabilities
A low-privilege logged-in user can perform unauthorized actions on the plugin, such as modifying pricing tables or settings.
Potential impact on your site
04Site Impact
Pricing tables and plugin settings could be modified by unauthorized users with basic WordPress access.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege WordPress account and trick a user into visiting a malicious link.
Key dates
06Disclosure timeline
May 23, 2023
CVE published
April 8, 2026
Record updated