What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Advanced Dynamic Pricing for WooCommerce plugin <= 4.1.5 on WordPress leading to rule type migration.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in Advanced Dynamic Pricing for WooCommerce plugin <= 4.1.5 on WordPress leading to rule type migration.
Explanation of Vulnerability in Simple Terms
Advanced Dynamic Pricing for WooCommerce versions up to 4.1.5 contain a cross-site request forgery vulnerability. An attacker can craft a malicious webpage that, when visited by a logged-in site administrator, performs unwanted actions such as modifying pricing rules or plugin settings without the admin's knowledge or consent.
What an attacker can do
Trick an admin into visiting a malicious page to modify plugin settings or pricing rules without their consent.
Potential impact on your site
Pricing rules or plugin configuration could be altered by attackers without your knowledge, affecting store operations.
Conditions required to exploit
Admin must be logged in and visit an attacker-controlled webpage.
Key dates
External resources
Related vulnerabilities