Advanced Dynamic Pricing for WooCommerce <= 4.9.3 - Cross-Site Request Forgery to Settings Update
medium
The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.9.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update plugin settings granted they can t...
- CVSS:
- 4.3
- Affected:
- up to 4.9.3
- Fixed in:
- 4.9.5
- Disclosed:
- Apr 17, 2025
CVE-2025-39453 on NVD →
Advanced Dynamic Pricing for WooCommerce [advanced-dynamic-pricing-for-woocommerce] < 4.9.5
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in algol.plus Advanced Dynamic Pricing for WooCommerce allows Cross Site Request Forgery. This issue affects Advanced Dynamic Pricing for WooCommerce: from n/a through 4.9.3.
- Affected:
- up to 4.9.5
- Fixed in:
- 4.9.5
- Disclosed:
- Apr 17, 2025
CVE-2025-39453 on NVD →
Advanced Dynamic Pricing for WooCommerce [advanced-dynamic-pricing-for-woocommerce] < 4.9.1
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AlgolPlus Advanced Dynamic Pricing for WooCommerce allows Reflected XSS. This issue affects Advanced Dynamic Pricing for WooCommerce: from n/a through 4.9.0.
- Affected:
- up to 4.9.1
- Fixed in:
- 4.9.1
- Disclosed:
- Jan 31, 2025
CVE-2025-24632 on NVD →
Advanced Dynamic Pricing for WooCommerce <= 4.9.0 - Reflected Cross-Site Scripting
medium
The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 4.9.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exe...
- CVSS:
- 6.1
- Affected:
- up to 4.9.0
- Fixed in:
- 4.9.1
- Disclosed:
- Jan 5, 2025
CVE-2025-24632 on NVD →
Advanced Dynamic Pricing for WooCommerce [advanced-dynamic-pricing-for-woocommerce] < 4.1.6
unknown
[en] Missing Authorization vulnerability in AlgolPlus Advanced Dynamic Pricing for WooCommerce.This issue affects Advanced Dynamic Pricing for WooCommerce: from n/a through 4.1.5.
- Affected:
- up to 4.1.6
- Fixed in:
- 4.1.6
- Disclosed:
- Jan 17, 2024
CVE-2022-40203 on NVD →
Advanced Dynamic Pricing for WooCommerce <= 4.1.5 - Cross-Site Request Forgery via handleSubmitAction function
medium
The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.5. This is due to missing or incorrect nonce validation on the handleSubmitAction function. This makes it possible for unauthenticated attackers to invoke this function via...
- CVSS:
- 5.4
- Affected:
- up to 4.1.5
- Fixed in:
- 4.1.6
- Disclosed:
- Feb 17, 2023
CVE-2022-40203 on NVD →
Advanced Dynamic Pricing for WooCommerce <= 4.1.5 - Cross-Site Request Forgery via migrateProductOnlyToCommon function
medium
The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.5. This is due to missing or incorrect nonce validation on the migrateProductOnlyToCommon function. This makes it possible for unauthenticated attackers to invoke this func...
- CVSS:
- 4.3
- Affected:
- up to 4.1.5
- Fixed in:
- 4.1.6
- Disclosed:
- Feb 17, 2023
CVE-2022-40203 on NVD →
Advanced Dynamic Pricing for WooCommerce <= 4.1.5 - Missing Authorization in migrateProductOnlyToCommon function
medium
The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the migrateProductOnlyToCommon function in versions up to, and including, 4.1.5. This makes it possible for authenticated attackers with subscriber-level access or hi...
- CVSS:
- 4.3
- Affected:
- up to 4.1.5
- Fixed in:
- 4.1.6
- Disclosed:
- Feb 17, 2023
CVE-2022-40203 on NVD →
Advanced Dynamic Pricing for WooCommerce <= 4.1.5 - Missing Authorization in migrateCommonToProductOnly function
medium
The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the migrateCommonToProductOnly function in versions up to, and including, 4.1.5. This makes it possible for authenticated attackers with subscriber-level access or hi...
- CVSS:
- 4.3
- Affected:
- up to 4.1.5
- Fixed in:
- 4.1.6
- Disclosed:
- Feb 17, 2023
CVE-2022-40203 on NVD →
Advanced Dynamic Pricing for WooCommerce <= 4.1.5 - Missing Authorization in ajaxCalculateSeveralProducts function
medium
The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajaxCalculateSeveralProducts function in versions up to, and including, 4.1.5. This makes it possible for authenticated attackers with subscriber-level access or highe...
- CVSS:
- 4.3
- Affected:
- up to 4.1.5
- Fixed in:
- 4.1.6
- Disclosed:
- Feb 17, 2023
CVE-2022-40203 on NVD →
Advanced Dynamic Pricing for WooCommerce <= 4.1.5 - Missing Authorization in ajaxCalculatePrice function
medium
The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajaxCalculatePrice function in versions up to, and including, 4.1.5. This makes it possible for authenticated attackers with subscriber-level access or higher to obtain...
- CVSS:
- 4.3
- Affected:
- up to 4.1.5
- Fixed in:
- 4.1.6
- Disclosed:
- Feb 17, 2023
CVE-2022-40203 on NVD →
Advanced Dynamic Pricing for WooCommerce <= 4.1.5 - Cross-Site Request Forgery via migrateCommonToProductOnly function
medium
The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.5. This is due to missing or incorrect nonce validation on the migrateCommonToProductOnly function. This makes it possible for unauthenticated attackers to invoke this func...
- CVSS:
- 4.3
- Affected:
- up to 4.1.5
- Fixed in:
- 4.1.6
- Disclosed:
- Feb 17, 2023
CVE-2022-40203 on NVD →
Advanced Dynamic Pricing for WooCommerce [advanced-dynamic-pricing-for-woocommerce] < 4.1.6
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Advanced Dynamic Pricing for WooCommerce plugin <= 4.1.5 on WordPress leading to rule type migration.
- Affected:
- up to 4.1.6
- Fixed in:
- 4.1.6
- Disclosed:
- Nov 9, 2022
CVE-2022-43488 on NVD →
Advanced Dynamic Pricing for WooCommerce [advanced-dynamic-pricing-for-woocommerce] < 4.1.6
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Advanced Dynamic Pricing for WooCommerce plugin <= 4.1.5 on WordPress leading to plugin settings import.
- Affected:
- up to 4.1.6
- Fixed in:
- 4.1.6
- Disclosed:
- Nov 8, 2022
CVE-2022-43491 on NVD →
Advanced Dynamic Pricing for WooCommerce <= 4.1.5 - Cross-Site Request Forgery
high
The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.5. This is due to missing or incorrect nonce validation on several functions related to data migration. This makes it possible for unauthenticated attackers to invoke those...
- CVSS:
- 8.8
- Affected:
- up to 4.1.5
- Fixed in:
- 4.1.6
- Disclosed:
- Oct 30, 2022
CVE-2022-43488 on NVD →
Advanced Dynamic Pricing for WooCommerce <= 4.1.5 - Cross-Site Request Forgery
high
The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.5. This is due to missing or incorrect nonce validation on several functions such as exportCSVBulkRangesAjaxCB(). This makes it possible for unauthenticated attackers to in...
- CVSS:
- 8.8
- Affected:
- up to 4.1.5
- Fixed in:
- 4.1.6
- Disclosed:
- Oct 26, 2022
CVE-2022-43491 on NVD →
Advanced Dynamic Pricing for WooCommerce <= 4.1.5 - Missing Authorization
medium
The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing access control on the exportCSVBulkRangesAjaxCB() function, in addition to several other functions, in versions up to, and including, 4.1.5. This makes it possible for authenticated attackers with mi...
- CVSS:
- 6.3
- Affected:
- up to 4.1.5
- Fixed in:
- 4.1.6
- Disclosed:
- Oct 25, 2022
Advanced Dynamic Pricing for WooCommerce [advanced-dynamic-pricing-for-woocommerce] < 4.1.6
unknown
The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing access control on the exportCSVBulkRangesAjaxCB() function, in addition to several other functions, in versions up to, and including, 4.1.5. This makes it possible for authenticated attackers with mi...
- Affected:
- up to 4.1.6
- Fixed in:
- 4.1.6
- Disclosed:
- Oct 25, 2022
Advanced Dynamic Pricing for WooCommerce [advanced-dynamic-pricing-for-woocommerce] < 4.1.4
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in AlgolPlus Advanced Dynamic Pricing for WooCommerce plugin <= 4.1.3 at WordPress.
- Affected:
- up to 4.1.4
- Fixed in:
- 4.1.4
- Disclosed:
- Sep 23, 2022
CVE-2022-38095 on NVD →
Advanced Dynamic Pricing for WooCommerce <= 4.1.3 - Cross-Site Request Forgery to Plugin Settings Update
high
The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.3. This is due to missing or incorrect nonce validation on the handleSubmitAction function. This makes it possible for unauthenticated attackers to update plugin settings,...
- CVSS:
- 8.8
- Affected:
- up to 4.1.3
- Fixed in:
- 4.1.4
- Disclosed:
- Sep 12, 2022
CVE-2022-38095 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database