Impact
The Dynamic Pricing With Discount Rules for WooCommerce WordPress plugin before version 5.0.0 contains an Ajax action that fails to check a nonce or the permissions of the requestor. As a result, the plugin reflects user supplied data back to the browser without sanitisation. An unauthenticated attacker can therefore embed malicious script in a crafted request and trigger its execution in the victim’s browser when the victim is induced to visit the exploit URL. The attacker can steal session cookies, deface the site, or perform actions on behalf of the victim.
Affected Systems
Any WordPress installation running the Dynamic Pricing With Discount Rules for WooCommerce plugin with a version earlier than 5.0.0 is affected. No additional vendor or product details are provided beyond the plugin identifier. Administrators should review the current plugin version on their sites.
Risk and Exploitability
The vulnerability enables remote client‑side code execution and is classified as a reflected XSS flaw (CWE‑79). The CVSS score of 7.1 indicates a high severity for this reflected XSS flaw. While the EPSS score indicates a very low probability of exploitation (< 1%), the lack of authentication checks means any user who visits a crafted URL could be impacted. The weakness is not listed in CISA’s KEV catalog. Attackers would need to entice a legitimate user to send the crafted Ajax request, which is a typical social‑engineering prerequisite for reflected XSS.
OpenCVE Enrichment