Impact
The flaw is an unauthenticated cross‑site scripting vulnerability in the Dynamic Pricing With Discount Rules for WooCommerce plugin, allowing an attacker to inject arbitrary JavaScript into pages rendered by the plugin. If executed, the injected script could deface the site, steal user session cookies, or perform further malicious actions on behalf of site visitors or administrators.
Affected Systems
WordPress sites that have the acowebs Dynamic Pricing With Discount Rules for WooCommerce plugin version 4.5.11 or earlier are exposed. All installations using any unpatched or older versions of the plugin remain at risk until the software is upgraded to a newer release.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑severity flaw that is exploitable by unauthenticated users via normal web traffic. The EPSS score of less than 1% denotes a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the plugin’s discount rule interface, where an attacker can supply malicious input that is not properly sanitized before being output to the browser. Because authentication is not required, any visitor can exploit the flaw on any affected site.
OpenCVE Enrichment