Description
Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions.
Published: 2026-07-27
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an unauthenticated cross‑site scripting vulnerability in the Dynamic Pricing With Discount Rules for WooCommerce plugin, allowing an attacker to inject arbitrary JavaScript into pages rendered by the plugin. If executed, the injected script could deface the site, steal user session cookies, or perform further malicious actions on behalf of site visitors or administrators.

Affected Systems

WordPress sites that have the acowebs Dynamic Pricing With Discount Rules for WooCommerce plugin version 4.5.11 or earlier are exposed. All installations using any unpatched or older versions of the plugin remain at risk until the software is upgraded to a newer release.

Risk and Exploitability

The CVSS score of 7.1 indicates a high‑severity flaw that is exploitable by unauthenticated users via normal web traffic. The EPSS score of less than 1% denotes a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the plugin’s discount rule interface, where an attacker can supply malicious input that is not properly sanitized before being output to the browser. Because authentication is not required, any visitor can exploit the flaw on any affected site.

Generated by OpenCVE AI on August 3, 2026 at 17:33 UTC.

Remediation

Vendor Solution

Update the WordPress Dynamic Pricing With Discount Rules for WooCommerce Plugin to the latest available version (at least 5.0.0).


OpenCVE Recommended Actions

  • Upgrade the WordPress Dynamic Pricing With Discount Rules for WooCommerce plugin to version 5.0.0 or later.
  • If an upgrade cannot be performed immediately, disable or remove the plugin to eliminate the attack surface.
  • Apply stringent input validation and proper HTML/JavaScript output encoding in any custom code that interacts with or displays data from the plugin to mitigate similar injection risks.

Generated by OpenCVE AI on August 3, 2026 at 17:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Acowebs
Acowebs dynamic Pricing With Discount Rules For Woocommerce
Wordpress
Wordpress wordpress
Vendors & Products Acowebs
Acowebs dynamic Pricing With Discount Rules For Woocommerce
Wordpress
Wordpress wordpress

Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions.
Title WordPress Dynamic Pricing With Discount Rules for WooCommerce plugin <= 4.5.11 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Acowebs Dynamic Pricing With Discount Rules For Woocommerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-27T14:58:18.183Z

Reserved: 2026-07-05T21:28:04.587Z

Link: CVE-2026-59556

cve-icon Vulnrichment

Updated: 2026-07-27T14:58:13.579Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T15:17:05.620

Modified: 2026-07-27T17:46:02.447

Link: CVE-2026-59556

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T17:45:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')