The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to unauthorized arbitrary file uploads due to an improper capability check on the 'validate_upload' function in versions up to, and including, 3.3.19. This makes it possible for authenticated attackers with a role that the administrator previously granted access to the plugin to upload arbitrary files on the affected site's server which may make remote code execution possible.
We have discovered 12,603 live websites that are affected by CVE-2023-2496.
Product | ![]() |
Category | Wordpress Plugins |
Vulnerable Domains | 12,603 live websites (68.43% of Go Pricing install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 43 versions ( 84.31% of all versions) |
![]() | 3,891 websites |
![]() | 1,371 websites |
![]() | 944 websites |
![]() | 526 websites |
![]() | 520 websites |
![]() | 476 websites |
![]() | 440 websites |
![]() | 417 websites |
![]() | 311 websites |
![]() | 231 websites |
.com | 5,329 websites |
.de | 649 websites |
.ru | 422 websites |
.nl | 408 websites |
.co.uk | 381 websites |
.it | 380 websites |
.org | 370 websites |
.fr | 288 websites |
.net | 277 websites |
.es | 259 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
***********.com | ![]() | **,*** | |
***********.com | ![]() | **,*** | |
*******.com | ![]() | **,*** | |
*******.com | ![]() | **,*** | |
********.com | ![]() | **,*** | |
***********.com | ![]() | **,*** | |
*******.hu | ![]() | **,*** | |
****.***.uk | ![]() | **,*** | |
*******.eu | ![]() | **,*** | |
********.com | ![]() | ***,*** |
FAQ