Stored Cross-Site Scripting in WholeSale Products Dynamic Pricing Management for WooCommerce
CVE-2026-4479
4.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 14 April 2026
What is CVE-2026-4479?
The WholeSale Products Dynamic Pricing Management plugin for WooCommerce is susceptible to a stored cross-site scripting vulnerability due to inadequate input sanitization and output escaping in its administrative settings. This flaw allows authenticated attackers with administrator-level permissions to inject arbitrary web scripts into pages. These scripts can execute whenever a user accesses the compromised page. The vulnerability impacts multi-site installations and environments where the 'unfiltered_html' feature has been disabled, posing significant security risks.
Affected Version(s)
WholeSale Products Dynamic Pricing Management WooCommerce 0 <= 1.2