CVE-2022-40203 MEDIUM

CVE-2022-40203: WordPress Advanced Dynamic Pricing for WooCommerce Plugin <= 4.1.5 is vulnerable to Broken Access Control

Vendor Algolplus
Product Advanced Dynamic Pricing for WooCommerce
Weakness CWE-862 · Missing authorization
Published January 17, 2024
Last update April 28, 2026

CVSS base score

6.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

What the vulnerability does

01Description

Missing Authorization vulnerability in AlgolPlus Advanced Dynamic Pricing for WooCommerce.This issue affects Advanced Dynamic Pricing for WooCommerce: from n/a through 4.1.5.

Explanation of Vulnerability in Simple Terms

02Summary

Advanced Dynamic Pricing for WooCommerce versions up to 4.1.5 lack proper authorization checks, allowing authenticated users with low privileges to read, modify, or delete pricing data they should not access. An attacker with a basic WooCommerce account can exploit this to view or alter product pricing configurations. Update to a version newer than 4.1.5 to resolve this issue.

What an attacker can do

03Attacker Capabilities

Read, modify, or delete pricing data and configurations without proper authorization.

Potential impact on your site

04Site Impact

Pricing rules can be altered or deleted by unauthorized users, potentially causing revenue loss or data corruption.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege WooCommerce user account; no user interaction required.

Key dates

06Disclosure timeline

January 17, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE