• SaasPricing worked well for me despite the lack of clear and detailed documentation. The plugin was fairly easy to use and integrated nicely with Elementor, allowing me to create pricing tables that fit my needs.

    However, I have temporarily deactivated the plugin after discovering a reported security vulnerability

    The SaasPricing plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    with a medium severity score (6.4/10 *). Until the developer releases a patched version, I consider it unsafe to keep the plugin active on any live site.

  • You must be logged in to reply to this review.