CVE · High

CVE-2025-24632 — Advanced Dynamic Pricing and Discount Rules for WooCommerce [advanced-dynamic-pricing-for-woocommerce] < 4.9.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-24632 Advanced Dynamic Pricing and Discount Rules for WooCommerce [advanced-dynamic-pricing-for-woocommerce] < 4.9.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 4.9.1 4.9.1 2025-01-05

CVE-2025-24632

The Advanced Dynamic Pricing for WooCommerce plugin for WordPress has a security flaw that allows attackers to inject malicious code into web pages, making it possible for them to execute arbitrary scripts on a user's device if the user clicks on a specially crafted link, without needing to be authenticated to do so. This vulnerability arises from the plugin's inadequate handling of user input and output, which fails to properly sanitize and escape potentially malicious data. As a result, an attacker can exploit this weakness to compromise the security of a WordPress site.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.