Stored Cross-Site Scripting Vulnerability in WooCommerce Dynamic Pricing and Discounts Plugin by WordPress
CVE-2021-4372
6.5MEDIUM
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 7 June 2023
Summary
The WooCommerce Dynamic Pricing and Discounts plugin for WordPress is susceptible to a stored cross-site scripting vulnerability that affects versions up to and including 2.4.1. This vulnerability arises from inadequate sanitization of settings imported via the import() function, allowing unauthenticated attackers to upload a settings file with malicious JavaScript. When an administrator accesses the settings area, this JavaScript executes, potentially compromising the Website. It emphasizes the importance of proper input validation to mitigate similar risks.
Affected Version(s)
WooCommerce Dynamic Pricing and Discounts * < 2.4.2
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jerome Bruandet