What the vulnerability does
01Description
The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to unauthorized arbitrary file uploads due to an improper capability check on the 'validate_upload' function in versions up to, and including, 3.3.19. This makes it possible for authenticated attackers with a role that the administrator previously granted access to the plugin to upload arbitrary files on the affected site's server which may make remote code execution possible.
Explanation of Vulnerability in Simple Terms
02Summary
Go Pricing contains an improper access control vulnerability affecting versions up to 3.3.19. An authenticated user with low privileges can perform unauthorized actions on pricing tables, including reading, modifying, or deleting data. The vulnerability requires user interaction and network access but can result in full compromise of confidentiality, integrity, and availability of affected pricing data.
What an attacker can do
03Attacker Capabilities
Read, modify, or delete pricing tables and associated data without proper authorization.
Potential impact on your site
04Site Impact
Pricing tables can be altered or deleted by low-privilege users, disrupting pricing display and potentially affecting sales.
Conditions required to exploit
05Prerequisites
Attacker must be logged in as a low-privilege user (e.g., subscriber) and trick a site admin into clicking a malicious link.
Key dates
06Disclosure timeline
May 23, 2023
CVE published
April 8, 2026
Record updated