What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Advanced Dynamic Pricing for WooCommerce plugin <= 4.1.5 on WordPress leading to plugin settings import.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in Advanced Dynamic Pricing for WooCommerce plugin <= 4.1.5 on WordPress leading to plugin settings import.
Explanation of Vulnerability in Simple Terms
The Advanced Dynamic Pricing for WooCommerce plugin through version 4.1.5 is vulnerable to cross-site request forgery (CSRF). An attacker can craft a malicious webpage that, when visited by a logged-in site administrator, performs unwanted actions on the site without their knowledge. This could allow modification of pricing rules or other plugin settings.
What an attacker can do
Trick an admin into visiting a malicious page to modify plugin settings or pricing rules without their consent.
Potential impact on your site
Pricing rules or plugin configuration could be altered by attackers without your knowledge or approval.
Conditions required to exploit
Admin must be logged in and visit an attacker-controlled webpage or click a malicious link.
Key dates
External resources
Related vulnerabilities