Description
Cross-Site Request Forgery (CSRF) vulnerability in ThemeHigh Dynamic Pricing and Discount Rules discount-and-dynamic-pricing allows Cross Site Request Forgery.This issue affects Dynamic Pricing and Discount Rules: from n/a through <= 2.2.9.
Published: 2025-06-06
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows attackers to forge requests that are processed by the plugin on behalf of an authenticated administrator, potentially altering pricing rules without explicit consent. This flaw directly abuses the lack of proper CSRF protection, enabling unauthorized changes to configuration and commerce settings. The weakness is classified as CWE‑352, a classic CSRF flaw that undermines the integrity of user‑initiated requests.

Affected Systems

Any WordPress site that has the ThemeHigh Dynamic Pricing and Discount Rules plugin installed with a version up to and including 2.2.9 is affected. The plugin is available through the WordPress plugin repository and may be present on a wide range of e‑commerce sites.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate impact, but the EPSS score of less than 1% suggests that exploit attempts are unlikely at this time. The issue is not listed in the CISA KEV catalog, further reducing its likely visibility in public exploits. An attacker can trigger the flaw by sending a crafted link to an administrator, thus exploiting the weaponized absence of CSRF tokens. While the attack requires the target to be logged in, ordinary visitors cannot trigger the modification. The path to exploitation is therefore widely available but limited to user sessions with administrative privileges.

Generated by OpenCVE AI on April 30, 2026 at 12:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to the latest version of ThemeHigh Dynamic Pricing and Discount Rules (>= 2.3.0) which removes the CSRF flaw.
  • If an upgrade cannot be performed immediately, disable the plugin from the WordPress admin panel to eliminate the attack surface.
  • Restrict administrative access to a small number of trusted users and enforce strong password policies to reduce the risk of accidental or malicious exploitation.

Generated by OpenCVE AI on April 30, 2026 at 12:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-17109 Cross-Site Request Forgery (CSRF) vulnerability in ThemeHigh Dynamic Pricing and Discount Rules allows Cross Site Request Forgery.This issue affects Dynamic Pricing and Discount Rules: from n/a through 2.2.9.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in ThemeHigh Dynamic Pricing and Discount Rules allows Cross Site Request Forgery.This issue affects Dynamic Pricing and Discount Rules: from n/a through 2.2.9. Cross-Site Request Forgery (CSRF) vulnerability in ThemeHigh Dynamic Pricing and Discount Rules discount-and-dynamic-pricing allows Cross Site Request Forgery.This issue affects Dynamic Pricing and Discount Rules: from n/a through <= 2.2.9.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Fri, 06 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 06 Jun 2025 11:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in ThemeHigh Dynamic Pricing and Discount Rules allows Cross Site Request Forgery.This issue affects Dynamic Pricing and Discount Rules: from n/a through 2.2.9.
Title WordPress Dynamic Pricing and Discount Rules plugin <= 2.2.9 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:58.772Z

Reserved: 2025-05-30T14:04:49.666Z

Link: CVE-2025-49077

cve-icon Vulnrichment

Updated: 2025-06-06T15:07:25.801Z

cve-icon NVD

Status : Deferred

Published: 2025-06-06T12:15:25.017

Modified: 2026-04-23T15:31:17.467

Link: CVE-2025-49077

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T12:30:16Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)