Reflected Cross-Site Scripting Vulnerability in Pricing Tables Plugin for WordPress
CVE-2026-6808
6.1MEDIUM
What is CVE-2026-6808?
The Pricing Tables for WP plugin, used in WordPress websites, is susceptible to a Reflected Cross-Site Scripting attack via the 'page' parameter. This vulnerability stems from inadequate input sanitization and output escaping practices within the plugin. As a result, unauthenticated attackers could craft malicious URLs that, if an administrator is deceived into clicking, allow these scripts to run in the context of the website. All versions up to and including 1.1.0 are affected, leaving many WordPress sites at risk of this exploit.
Affected Version(s)
Pricing Tables for WP 0 <= 1.1.0