Impact
Improper neutralization of input in the Advanced Dynamic Pricing for WooCommerce plugin allows an attacker to embed malicious script into a page that is rendered to the victim. Based on the description, it is inferred that the reflected XSS could be used to steal session cookies, deface the site, or execute arbitrary client‑side code on the victim’s browser. The vulnerability is based on CWE‑79 and is classified as a client‑side code injection flaw that compromises confidentiality and integrity of the user session.
Affected Systems
The affected product is Advanced Dynamic Pricing for WooCommerce, a plugin developed by Algol Plus. Versions from the initial release up to and including 4.9.0 contain the flaw; any site running 4.9.0 or earlier is vulnerable. No specific sub‑versions are enumerated beyond the upper bound.
Risk and Exploitability
With a CVSS score of 7.1 the flaw is considered high severity, and the EPSS score of <1% indicates a low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote, relying on an attacker supplying crafted input that is reflected in the plugin’s output. Anyone with the ability to influence the request parameters—such as site visitors or authenticated users with permission to trigger the pricing logic—could potentially exploit the flaw.
OpenCVE Enrichment
EUVD