Stored Cross-Site Scripting Vulnerability in WooCommerce Dynamic Pricing and Discounts Plugin by WordPress
CVE-2021-4372

6.5MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
7 June 2023

Summary

The WooCommerce Dynamic Pricing and Discounts plugin for WordPress is susceptible to a stored cross-site scripting vulnerability that affects versions up to and including 2.4.1. This vulnerability arises from inadequate sanitization of settings imported via the import() function, allowing unauthenticated attackers to upload a settings file with malicious JavaScript. When an administrator accesses the settings area, this JavaScript executes, potentially compromising the Website. It emphasizes the importance of proper input validation to mitigate similar risks.

Affected Version(s)

WooCommerce Dynamic Pricing and Discounts * < 2.4.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jerome Bruandet
.