Stored Cross-Site Scripting Vulnerability in WooCommerce Dynamic Pricing and Discounts Plugin by WordPress
CVE-2021-4372
6.5MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 7 June 2023
What is CVE-2021-4372?
The WooCommerce Dynamic Pricing and Discounts plugin for WordPress is susceptible to a stored cross-site scripting vulnerability that affects versions up to and including 2.4.1. This vulnerability arises from inadequate sanitization of settings imported via the import() function, allowing unauthenticated attackers to upload a settings file with malicious JavaScript. When an administrator accesses the settings area, this JavaScript executes, potentially compromising the Website. It emphasizes the importance of proper input validation to mitigate similar risks.
Affected Version(s)
WooCommerce Dynamic Pricing and Discounts * < 2.4.2