What the vulnerability does
01Description
Missing Authorization vulnerability in QuanticaLabs CSS3 Compare Pricing Tables for WordPress css3_web_pricing_tables_grids allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CSS3 Compare Pricing Tables for WordPress: from n/a through <= 11.6.
Explanation of Vulnerability in Simple Terms
02Summary
The CSS3 Compare Pricing Tables plugin for WordPress does not properly check user permissions before allowing modifications to pricing table data. A logged-in user with low privileges can alter or delete pricing tables they should not have access to. The plugin does not validate authorization on sensitive operations, allowing privilege escalation within the site.
What an attacker can do
03Attacker Capabilities
A low-privilege logged-in user can modify or delete pricing tables belonging to other users or the site.
Potential impact on your site
04Site Impact
Pricing table data can be corrupted or deleted by users who should only have view access, disrupting site functionality and content integrity.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege WordPress user account (e.g., Subscriber or Contributor role).
Key dates
06Disclosure timeline
May 16, 2025
CVE published
April 28, 2026
Record updated