Wholesale Suite – B2B, Dynamic Pricing & WooCommerce Wholesale Prices [woocommerce-wholesale-prices] <= 2.2.6 (unfixed)
unknown
[en] Incorrect Privilege Assignment vulnerability in Josh Kohlbach Wholesale Suite woocommerce-wholesale-prices allows Privilege Escalation.This issue affects Wholesale Suite: from n/a through <= 2.2.6.
- Affected:
- up to 2.2.6
- Fix:
- No patched version reported
- Disclosed:
- Mar 5, 2026
CVE-2026-27541 on NVD →
Wholesale Suite <= 2.2.6 - Authenticated (Shop Manager) Privilege Escalation
high
The Wholesale Suite – B2B, Dynamic Pricing & WooCommerce Wholesale Prices plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.2.6.This makes it possible for authenticated attackers, with Shop Manager-level access and above, to elevate their privileges to that of an adminis...
- CVSS:
- 7.2
- Affected:
- up to 2.2.6
- Fixed in:
- 2.2.7
- Disclosed:
- Feb 20, 2026
CVE-2026-27541 on NVD →
Wholesale Suite – B2B, Dynamic Pricing & WooCommerce Wholesale Prices [woocommerce-wholesale-prices] <= 2.2.4.2 (unfixed)
unknown
[en] Incorrect Privilege Assignment vulnerability in Josh Kohlbach Wholesale Suite woocommerce-wholesale-prices allows Privilege Escalation.This issue affects Wholesale Suite: from n/a through <= 2.2.4.2.
- Affected:
- up to 2.2.4.2
- Fix:
- No patched version reported
- Disclosed:
- Oct 22, 2025
CVE-2025-49924 on NVD →
Wholesale Suite <= 2.2.4.2 - Authenticated (Shop Manager+) Privilege Escalation
high
The Wholesale Suite – B2B, Dynamic Pricing & Wholesale Prices for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.2.4.2. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to gain administrative-level access.
- CVSS:
- 7.2
- Affected:
- up to 2.2.4.2
- Fixed in:
- 2.2.5
- Disclosed:
- Jul 23, 2025
CVE-2025-49924 on NVD →
Wholesale Suite – B2B, Dynamic Pricing & WooCommerce Wholesale Prices [woocommerce-wholesale-prices] < 2.2.0
unknown
[en] Missing Authorization vulnerability in Rymera Web Co Wholesale Suite allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Wholesale Suite: from n/a through 2.1.12.
- Affected:
- up to 2.2.0
- Fixed in:
- 2.2.0
- Disclosed:
- Nov 1, 2024
CVE-2024-38745 on NVD →
Wholesale Suite <= 2.1.12 - Missing Authorization
medium
The Wholesale Suite – WooCommerce Wholesale Prices, B2B, Catalog Mode, Order Form, Wholesale User Roles, Dynamic Pricing & More plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.1.12. This makes it possible for unauthenticat...
- CVSS:
- 5.3
- Affected:
- up to 2.1.12
- Fixed in:
- 2.2.0
- Disclosed:
- Jul 11, 2024
CVE-2024-38745 on NVD →
Wholesale Suite – B2B, Dynamic Pricing & WooCommerce Wholesale Prices [woocommerce-wholesale-prices] < 2.1.5.1
unknown
[en] Missing Authorization vulnerability in Rymera Web Co Wholesale Suite – WooCommerce Wholesale Prices, B2B, Catalog Mode, Order Form, Wholesale User Roles, Dynamic Pricing & More.This issue affects Wholesale Suite – WooCommerce Wholesale Prices, B2B, Catalog Mode, Order Form, Wholesale User Roles, Dynamic Pricing &...
- Affected:
- up to 2.1.5.1
- Fixed in:
- 2.1.5.1
- Disclosed:
- Jan 8, 2024
CVE-2022-34344 on NVD →
Wholesale Suite – B2B, Dynamic Pricing & WooCommerce Wholesale Prices [woocommerce-wholesale-prices] < 2.1.5.1
unknown
[en] Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in Rymera Web Co Wholesale Suite plugin <= 2.1.5 versions.
- Affected:
- up to 2.1.5.1
- Fixed in:
- 2.1.5.1
- Disclosed:
- May 9, 2023
CVE-2022-41640 on NVD →
Wholesale Suite <= 2.1.5 - Missing Authorization to Plugin Settings Change
medium
The Wholesale Suite plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the edit_wholesale_role function in versions up to, and including, 2.1.5. This makes it possible for authenticated attackers with subscriber-level privileges to change the plugin's settings.
- CVSS:
- 4.3
- Affected:
- up to 2.1.5
- Fixed in:
- 2.1.6
- Disclosed:
- Feb 27, 2023
CVE-2022-34344 on NVD →
Wholesale Suite <= 2.1.5 - Authenticated (Subscriber+) Cross-Site Scripting
medium
The Wholesale Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'role' parameters in versions up to, and including, 2.1.5 due to insufficient input sanitization and output escaping. This makes it possible for subscriber-level, and above, attackers to inject arbitrary web scripts in pages t...
- CVSS:
- 6.4
- Affected:
- up to 2.1.5
- Fixed in:
- 2.1.5.1
- Disclosed:
- Nov 28, 2022
CVE-2022-41640 on NVD →
Wholesale Suite <= 2.1.5 - Cross-Site Request Forgery
high
The Wholesale Suite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.5. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to invoke those functions, via forged request granted they can tri...
- CVSS:
- 8.8
- Affected:
- up to 2.1.5
- Fixed in:
- 2.1.5.1
- Disclosed:
- Oct 19, 2022
Wholesale Suite – B2B, Dynamic Pricing & WooCommerce Wholesale Prices [woocommerce-wholesale-prices] < 2.1.5.1
unknown
The Wholesale Suite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.5. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to invoke those functions, via forged request granted they can tri...
- Affected:
- up to 2.1.5.1
- Fixed in:
- 2.1.5.1
- Disclosed:
- Oct 19, 2022
Wholesale Suite – B2B, Dynamic Pricing & WooCommerce Wholesale Prices [woocommerce-wholesale-prices] < 2.1.5.1
unknown
Update the WordPress Wholesale Suite plugin to the latest available version (at least 2.1.5.1).
Dave Jong discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Wholesale Suite Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and othe...
- Affected:
- up to 2.1.5.1
- Fixed in:
- 2.1.5.1
Wholesale Suite – B2B, Dynamic Pricing & WooCommerce Wholesale Prices [woocommerce-wholesale-prices] < 2.1.5.1
unknown
The plugin does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks.
- Affected:
- up to 2.1.5.1
- Fixed in:
- 2.1.5.1
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database