Cross Site Scripting Vulnerability in Dynamic Pricing With Discount Rules for WooCommerce by PatchStack
CVE-2026-59556
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 27 July 2026
What is CVE-2026-59556?
An unauthenticated cross site scripting vulnerability exists in the Dynamic Pricing With Discount Rules for WooCommerce plugin. This vulnerability affects versions up to 4.5.11, allowing attackers to exploit the weakness and potentially execute malicious scripts in the context of a victim’s session, posing significant security risks to users and their data.
Affected Version(s)
Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Denny Abraham Sinaga | Patchstack Bug Bounty Program