Executive brief
The Supsystic Pricing Table plugin for WordPress, which is used to create comparison and pricing charts, contains security flaws that allow attackers to manipulate the website's database. An unauthenticated attacker can use these flaws to extract sensitive information from the database or inject malicious scripts that target site visitors. This could lead to data theft, unauthorized access to the website's backend, or the compromise of user sessions.
Technical details
The Supsystic Pricing Table plugin (versions 1.8.7 and below) is vulnerable to unauthenticated SQL injection and stored cross-site scripting. The SQL injection exists in the 'sidx' GET parameter during the 'getListForTbl' action, where user input is not properly sanitized before being used in a database query; this allows for boolean-based and time-based blind SQL injection. Additionally, the plugin fails to sanitize the 'Edit name' and 'Edit HTML' fields, allowing authenticated users (or those with access to the table editor) to inject malicious JavaScript. These scripts execute when a user views the pricing table or the 'Show All Tables' section in the admin dashboard. A patch was reportedly released around December 2020.
Affected products
- Supsystic Pricing Table by Supsystic <= 1.8.7
Timeline
- 2020-07-24: disclosed: Vulnerability discovered by researcher Erik David Martin
- 2020-07-25: other: Vendor notified of the vulnerabilities
- 2020-12-07: patched: Vulnerability reportedly patched following contact with WordPress Plugin Security team
- 2021-02-08: other: Exploit code published on Exploit-DB
- 2026-05-16: advisory: NVD/VulnCheck advisory published