CVE Database /
CVE-2022-43491
CVE · Medium
CVE-2022-43491 — Advanced Dynamic Pricing and Discount Rules for WooCommerce [advanced-dynamic-pricing-for-woocommerce] < 4.1.6
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-43491
|
Advanced Dynamic Pricing and Discount Rules for WooCommerce [advanced-dynamic-pricing-for-woocommerce] < 4.1.6 |
Cross-Site Request Forgery (CSRF) |
Medium
5.4
|
< 4.1.6
|
4.1.6 |
2022-10-26 |
—
|
CVE-2022-43491
The Advanced Dynamic Pricing for WooCommerce plugin through version 4.1.5 contains a cross-site request forgery vulnerability stemming from insufficient nonce verification on multiple functions including exportCSVBulkRangesAjaxCB(). Unauthenticated attackers could exploit this flaw to manipulate plugin settings and import configuration data if they successfully deceive an administrator into clicking a malicious link. The vulnerability was resolved in version 4.1.6.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings