The plugin does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high-privilege users such as admins.
id: CVE-2023-0900
info:
name: AP Pricing Tables Lite <= 1.1.6 - SQL Injection
author: r3Y3r53
...