plugin

Woo Wholesale Pricing Vulnerabilities

2 known security issues reported for the Woo Wholesale Pricing WordPress plugin. Most recent disclosed Jul 28, 2026.

1 high 1 medium

Running Woo Wholesale Pricing on your site? Check whether your installed version is affected.

Scan your site free

Wholesale for WooCommerce <= 2.0.5 - Authenticated (Author+) Privilege Escalation via 'user_role_set' Parameter

high

The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This is due to the `save_requests_meta()` function applying only `sanitize_text_field()` to the `user_role_set` POST parameter before passing it directly to `WP_User::add_role()`, with n...

CVSS:
8.8
Affected:
up to 2.0.5
Fixed in:
2.0.6
Disclosed:
Jul 28, 2026

CVE-2026-12144 on NVD →

Freemius SDK <= 2.4.2 - Missing Authorization Checks

medium

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...

CVSS:
6.3
Affected:
up to 1.6.1
Fixed in:
1.6.1
Disclosed:
Mar 4, 2022

CVE-2022-4974 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database