CVE Database /
CVE-2022-43488
CVE · Medium
CVE-2022-43488 — Advanced Dynamic Pricing and Discount Rules for WooCommerce [advanced-dynamic-pricing-for-woocommerce] < 4.1.6
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-43488
|
Advanced Dynamic Pricing and Discount Rules for WooCommerce [advanced-dynamic-pricing-for-woocommerce] < 4.1.6 |
Cross-Site Request Forgery (CSRF) |
Medium
5.4
|
< 4.1.6
|
4.1.6 |
2022-10-30 |
—
|
CVE-2022-43488
The Advanced Dynamic Pricing for WooCommerce plugin through version 4.1.5 contains a cross-site request forgery vulnerability affecting multiple data migration functions that lack proper nonce verification. An attacker can craft malicious requests that, if clicked by an administrator, would allow unauthorized modification of plugin settings. The vulnerability affects all versions prior to 4.1.6 and requires social engineering to trick an authenticated admin user into clicking a malicious link.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings