Reflected Cross-Site Scripting Vulnerability in Pricing Tables Plugin for WordPress
CVE-2026-6808

6.1MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
12 May 2026

What is CVE-2026-6808?

The Pricing Tables for WP plugin, used in WordPress websites, is susceptible to a Reflected Cross-Site Scripting attack via the 'page' parameter. This vulnerability stems from inadequate input sanitization and output escaping practices within the plugin. As a result, unauthenticated attackers could craft malicious URLs that, if an administrator is deceived into clicking, allow these scripts to run in the context of the website. All versions up to and including 1.1.0 are affected, leaving many WordPress sites at risk of this exploit.

Affected Version(s)

Pricing Tables for WP 0 <= 1.1.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Julian Chibuike Nwadinobi
.