Executive brief
A security vulnerability exists in the Dynamic Pricing With Discount Rules for WooCommerce plugin, which is used by online stores to manage complex sales and promotions. An attacker could inject malicious scripts into the website, potentially leading to unauthorized actions being performed in a site administrator's browser, such as redirecting customers to fraudulent sites or stealing session information. This issue affects all versions up to and including 4.5.11 and requires a user to interact with a malicious link or page.
Technical details
The Dynamic Pricing With Discount Rules for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Reflected Cross-Site Scripting (XSS) due to improper neutralization of input during web page generation (CWE-79). The vulnerability exists in versions up to and including 4.5.11. An unauthenticated attacker can exploit this by tricking a privileged user (such as an administrator) into clicking a specially crafted link or visiting a malicious page. Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session, which can lead to session hijacking or unauthorized administrative actions. The issue is resolved in version 5.0.0.
Affected products
- Acowebs Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11
Timeline
- 2026-04-29: disclosed: Reported by Denny Abraham Sinaga
- 2026-07-24: advisory: Patchstack advisory published
- 2026-07-27: patched: NVD publication date; fix available in version 5.0.0