plugin

Advanced Dynamic Pricing For Woocommerce Vulnerabilities

20 known security issues reported for the Advanced Dynamic Pricing For Woocommerce WordPress plugin. Most recent disclosed Apr 17, 2025.

3 high 10 medium

Running Advanced Dynamic Pricing For Woocommerce on your site? Check whether your installed version is affected.

Scan your site free

Advanced Dynamic Pricing for WooCommerce <= 4.9.3 - Cross-Site Request Forgery to Settings Update

medium

The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.9.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update plugin settings granted they can t...

CVSS:
4.3
Affected:
up to 4.9.3
Fixed in:
4.9.5
Disclosed:
Apr 17, 2025

CVE-2025-39453 on NVD →

Advanced Dynamic Pricing for WooCommerce [advanced-dynamic-pricing-for-woocommerce] < 4.9.5

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in algol.plus Advanced Dynamic Pricing for WooCommerce allows Cross Site Request Forgery. This issue affects Advanced Dynamic Pricing for WooCommerce: from n/a through 4.9.3.

Affected:
up to 4.9.5
Fixed in:
4.9.5
Disclosed:
Apr 17, 2025

CVE-2025-39453 on NVD →

Advanced Dynamic Pricing for WooCommerce [advanced-dynamic-pricing-for-woocommerce] < 4.9.1

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AlgolPlus Advanced Dynamic Pricing for WooCommerce allows Reflected XSS. This issue affects Advanced Dynamic Pricing for WooCommerce: from n/a through 4.9.0.

Affected:
up to 4.9.1
Fixed in:
4.9.1
Disclosed:
Jan 31, 2025

CVE-2025-24632 on NVD →

Advanced Dynamic Pricing for WooCommerce <= 4.9.0 - Reflected Cross-Site Scripting

medium

The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 4.9.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exe...

CVSS:
6.1
Affected:
up to 4.9.0
Fixed in:
4.9.1
Disclosed:
Jan 5, 2025

CVE-2025-24632 on NVD →

Advanced Dynamic Pricing for WooCommerce [advanced-dynamic-pricing-for-woocommerce] < 4.1.6

unknown

[en] Missing Authorization vulnerability in AlgolPlus Advanced Dynamic Pricing for WooCommerce.This issue affects Advanced Dynamic Pricing for WooCommerce: from n/a through 4.1.5.

Affected:
up to 4.1.6
Fixed in:
4.1.6
Disclosed:
Jan 17, 2024

CVE-2022-40203 on NVD →

Advanced Dynamic Pricing for WooCommerce <= 4.1.5 - Cross-Site Request Forgery via handleSubmitAction function

medium

The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.5. This is due to missing or incorrect nonce validation on the handleSubmitAction function. This makes it possible for unauthenticated attackers to invoke this function via...

CVSS:
5.4
Affected:
up to 4.1.5
Fixed in:
4.1.6
Disclosed:
Feb 17, 2023

CVE-2022-40203 on NVD →

Advanced Dynamic Pricing for WooCommerce <= 4.1.5 - Cross-Site Request Forgery via migrateProductOnlyToCommon function

medium

The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.5. This is due to missing or incorrect nonce validation on the migrateProductOnlyToCommon function. This makes it possible for unauthenticated attackers to invoke this func...

CVSS:
4.3
Affected:
up to 4.1.5
Fixed in:
4.1.6
Disclosed:
Feb 17, 2023

CVE-2022-40203 on NVD →

Advanced Dynamic Pricing for WooCommerce <= 4.1.5 - Missing Authorization in migrateProductOnlyToCommon function

medium

The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the migrateProductOnlyToCommon function in versions up to, and including, 4.1.5. This makes it possible for authenticated attackers with subscriber-level access or hi...

CVSS:
4.3
Affected:
up to 4.1.5
Fixed in:
4.1.6
Disclosed:
Feb 17, 2023

CVE-2022-40203 on NVD →

Advanced Dynamic Pricing for WooCommerce <= 4.1.5 - Missing Authorization in migrateCommonToProductOnly function

medium

The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the migrateCommonToProductOnly function in versions up to, and including, 4.1.5. This makes it possible for authenticated attackers with subscriber-level access or hi...

CVSS:
4.3
Affected:
up to 4.1.5
Fixed in:
4.1.6
Disclosed:
Feb 17, 2023

CVE-2022-40203 on NVD →

Advanced Dynamic Pricing for WooCommerce <= 4.1.5 - Missing Authorization in ajaxCalculateSeveralProducts function

medium

The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajaxCalculateSeveralProducts function in versions up to, and including, 4.1.5. This makes it possible for authenticated attackers with subscriber-level access or highe...

CVSS:
4.3
Affected:
up to 4.1.5
Fixed in:
4.1.6
Disclosed:
Feb 17, 2023

CVE-2022-40203 on NVD →

Advanced Dynamic Pricing for WooCommerce <= 4.1.5 - Missing Authorization in ajaxCalculatePrice function

medium

The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajaxCalculatePrice function in versions up to, and including, 4.1.5. This makes it possible for authenticated attackers with subscriber-level access or higher to obtain...

CVSS:
4.3
Affected:
up to 4.1.5
Fixed in:
4.1.6
Disclosed:
Feb 17, 2023

CVE-2022-40203 on NVD →

Advanced Dynamic Pricing for WooCommerce <= 4.1.5 - Cross-Site Request Forgery via migrateCommonToProductOnly function

medium

The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.5. This is due to missing or incorrect nonce validation on the migrateCommonToProductOnly function. This makes it possible for unauthenticated attackers to invoke this func...

CVSS:
4.3
Affected:
up to 4.1.5
Fixed in:
4.1.6
Disclosed:
Feb 17, 2023

CVE-2022-40203 on NVD →

Advanced Dynamic Pricing for WooCommerce [advanced-dynamic-pricing-for-woocommerce] < 4.1.6

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Advanced Dynamic Pricing for WooCommerce plugin <= 4.1.5 on WordPress leading to rule type migration.

Affected:
up to 4.1.6
Fixed in:
4.1.6
Disclosed:
Nov 9, 2022

CVE-2022-43488 on NVD →

Advanced Dynamic Pricing for WooCommerce [advanced-dynamic-pricing-for-woocommerce] < 4.1.6

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Advanced Dynamic Pricing for WooCommerce plugin <= 4.1.5 on WordPress leading to plugin settings import.

Affected:
up to 4.1.6
Fixed in:
4.1.6
Disclosed:
Nov 8, 2022

CVE-2022-43491 on NVD →

Advanced Dynamic Pricing for WooCommerce <= 4.1.5 - Cross-Site Request Forgery

high

The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.5. This is due to missing or incorrect nonce validation on several functions related to data migration. This makes it possible for unauthenticated attackers to invoke those...

CVSS:
8.8
Affected:
up to 4.1.5
Fixed in:
4.1.6
Disclosed:
Oct 30, 2022

CVE-2022-43488 on NVD →

Advanced Dynamic Pricing for WooCommerce <= 4.1.5 - Cross-Site Request Forgery

high

The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.5. This is due to missing or incorrect nonce validation on several functions such as exportCSVBulkRangesAjaxCB(). This makes it possible for unauthenticated attackers to in...

CVSS:
8.8
Affected:
up to 4.1.5
Fixed in:
4.1.6
Disclosed:
Oct 26, 2022

CVE-2022-43491 on NVD →

Advanced Dynamic Pricing for WooCommerce <= 4.1.5 - Missing Authorization

medium

The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing access control on the exportCSVBulkRangesAjaxCB() function, in addition to several other functions, in versions up to, and including, 4.1.5. This makes it possible for authenticated attackers with mi...

CVSS:
6.3
Affected:
up to 4.1.5
Fixed in:
4.1.6
Disclosed:
Oct 25, 2022

Advanced Dynamic Pricing for WooCommerce [advanced-dynamic-pricing-for-woocommerce] < 4.1.6

unknown

The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing access control on the exportCSVBulkRangesAjaxCB() function, in addition to several other functions, in versions up to, and including, 4.1.5. This makes it possible for authenticated attackers with mi...

Affected:
up to 4.1.6
Fixed in:
4.1.6
Disclosed:
Oct 25, 2022

Advanced Dynamic Pricing for WooCommerce [advanced-dynamic-pricing-for-woocommerce] < 4.1.4

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in AlgolPlus Advanced Dynamic Pricing for WooCommerce plugin <= 4.1.3 at WordPress.

Affected:
up to 4.1.4
Fixed in:
4.1.4
Disclosed:
Sep 23, 2022

CVE-2022-38095 on NVD →

Advanced Dynamic Pricing for WooCommerce <= 4.1.3 - Cross-Site Request Forgery to Plugin Settings Update

high

The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.3. This is due to missing or incorrect nonce validation on the handleSubmitAction function. This makes it possible for unauthenticated attackers to update plugin settings,...

CVSS:
8.8
Affected:
up to 4.1.3
Fixed in:
4.1.4
Disclosed:
Sep 12, 2022

CVE-2022-38095 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database