PT-2023-12483 · WordPress · Elex Woocommerce Dynamic Pricing/Discounts
Jerome Bruandet
·
Published
2023-06-07
·
Updated
2023-06-13
·
CVE-2021-4372
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WooCommerce Dynamic Pricing and Discounts plugin for WordPress versions up to, and including, 2.4.1
Description
The issue is related to Stored Cross-Site Scripting due to missing sanitization on settings imported via the
import() function. This allows unauthenticated attackers to import a settings file containing malicious JavaScript, which would execute when an administrator accesses the settings area of the site.Recommendations
For versions up to, and including, 2.4.1, update to a version higher than 2.4.1 to resolve the issue. As a temporary workaround, consider restricting access to the settings import functionality to prevent malicious settings files from being imported.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Elex Woocommerce Dynamic Pricing/Discounts