The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.3.19 via deserialization of untrusted input from the 'go_pricing' shortcode 'data' parameter. This allows authenticated attackers, with subscriber-level permissions and above, to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
We have discovered 11,228 live websites that are affected by CVE-2023-2500.
Product | ![]() |
Category | Wordpress Plugins |
Vulnerable Domains | 11,228 live websites (100% of Go Pricing install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 0 versions ( less than 0.1% of all versions) |
![]() | 2,899 websites |
![]() | 1,024 websites |
![]() | 731 websites |
![]() | 712 websites |
![]() | 554 websites |
![]() | 492 websites |
![]() | 471 websites |
![]() | 398 websites |
![]() | 268 websites |
![]() | 238 websites |
.com | 4,667 websites |
.de | 569 websites |
.it | 534 websites |
.ru | 390 websites |
.co.uk | 342 websites |
.nl | 341 websites |
.org | 316 websites |
.fr | 249 websites |
.net | 246 websites |
.es | 235 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
***********.com | ![]() | **,*** | |
*******.com | ![]() | **,*** | |
*******.com | ![]() | **,*** | |
********.com | ![]() | **,*** | |
***********.com | ![]() | **,*** | |
*******.hu | ![]() | **,*** | |
****.***.uk | ![]() | **,*** | |
*******.eu | ![]() | **,*** | |
************************.com | ![]() | **,*** | |
********.com | ![]() | ***,*** |
FAQ