What the vulnerability does
01Description
Missing Authorization vulnerability in AlgolPlus Advanced Dynamic Pricing for WooCommerce.This issue affects Advanced Dynamic Pricing for WooCommerce: from n/a through 4.1.5.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in AlgolPlus Advanced Dynamic Pricing for WooCommerce.This issue affects Advanced Dynamic Pricing for WooCommerce: from n/a through 4.1.5.
Explanation of Vulnerability in Simple Terms
Advanced Dynamic Pricing for WooCommerce versions up to 4.1.5 lack proper authorization checks, allowing authenticated users with low privileges to read, modify, or delete pricing data they should not access. An attacker with a basic WooCommerce account can exploit this to view or alter product pricing configurations. Update to a version newer than 4.1.5 to resolve this issue.
What an attacker can do
Read, modify, or delete pricing data and configurations without proper authorization.
Potential impact on your site
Pricing rules can be altered or deleted by unauthorized users, potentially causing revenue loss or data corruption.
Conditions required to exploit
Attacker must have a low-privilege WooCommerce user account; no user interaction required.
Key dates
External resources
Related vulnerabilities