plugin

Woocommerce Wholesale Prices Vulnerabilities

14 known security issues reported for the Woocommerce Wholesale Prices WordPress plugin. Most recent disclosed Mar 5, 2026.

3 high 3 medium

Running Woocommerce Wholesale Prices on your site? Check whether your installed version is affected.

Scan your site free

Wholesale Suite – B2B, Dynamic Pricing &amp; WooCommerce Wholesale Prices [woocommerce-wholesale-prices] <= 2.2.6 (unfixed)

unknown

[en] Incorrect Privilege Assignment vulnerability in Josh Kohlbach Wholesale Suite woocommerce-wholesale-prices allows Privilege Escalation.This issue affects Wholesale Suite: from n/a through <= 2.2.6.

Affected:
up to 2.2.6
Fix:
No patched version reported
Disclosed:
Mar 5, 2026

CVE-2026-27541 on NVD →

Wholesale Suite <= 2.2.6 - Authenticated (Shop Manager) Privilege Escalation

high

The Wholesale Suite – B2B, Dynamic Pricing & WooCommerce Wholesale Prices plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.2.6.This makes it possible for authenticated attackers, with Shop Manager-level access and above, to elevate their privileges to that of an adminis...

CVSS:
7.2
Affected:
up to 2.2.6
Fixed in:
2.2.7
Disclosed:
Feb 20, 2026

CVE-2026-27541 on NVD →

Wholesale Suite – B2B, Dynamic Pricing &amp; WooCommerce Wholesale Prices [woocommerce-wholesale-prices] <= 2.2.4.2 (unfixed)

unknown

[en] Incorrect Privilege Assignment vulnerability in Josh Kohlbach Wholesale Suite woocommerce-wholesale-prices allows Privilege Escalation.This issue affects Wholesale Suite: from n/a through <= 2.2.4.2.

Affected:
up to 2.2.4.2
Fix:
No patched version reported
Disclosed:
Oct 22, 2025

CVE-2025-49924 on NVD →

Wholesale Suite <= 2.2.4.2 - Authenticated (Shop Manager+) Privilege Escalation

high

The Wholesale Suite – B2B, Dynamic Pricing & Wholesale Prices for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.2.4.2. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to gain administrative-level access.

CVSS:
7.2
Affected:
up to 2.2.4.2
Fixed in:
2.2.5
Disclosed:
Jul 23, 2025

CVE-2025-49924 on NVD →

Wholesale Suite – B2B, Dynamic Pricing &amp; WooCommerce Wholesale Prices [woocommerce-wholesale-prices] < 2.2.0

unknown

[en] Missing Authorization vulnerability in Rymera Web Co Wholesale Suite allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Wholesale Suite: from n/a through 2.1.12.

Affected:
up to 2.2.0
Fixed in:
2.2.0
Disclosed:
Nov 1, 2024

CVE-2024-38745 on NVD →

Wholesale Suite <= 2.1.12 - Missing Authorization

medium

The Wholesale Suite – WooCommerce Wholesale Prices, B2B, Catalog Mode, Order Form, Wholesale User Roles, Dynamic Pricing & More plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.1.12. This makes it possible for unauthenticat...

CVSS:
5.3
Affected:
up to 2.1.12
Fixed in:
2.2.0
Disclosed:
Jul 11, 2024

CVE-2024-38745 on NVD →

Wholesale Suite – B2B, Dynamic Pricing &amp; WooCommerce Wholesale Prices [woocommerce-wholesale-prices] < 2.1.5.1

unknown

[en] Missing Authorization vulnerability in Rymera Web Co Wholesale Suite – WooCommerce Wholesale Prices, B2B, Catalog Mode, Order Form, Wholesale User Roles, Dynamic Pricing & More.This issue affects Wholesale Suite – WooCommerce Wholesale Prices, B2B, Catalog Mode, Order Form, Wholesale User Roles, Dynamic Pricing &...

Affected:
up to 2.1.5.1
Fixed in:
2.1.5.1
Disclosed:
Jan 8, 2024

CVE-2022-34344 on NVD →

Wholesale Suite – B2B, Dynamic Pricing &amp; WooCommerce Wholesale Prices [woocommerce-wholesale-prices] < 2.1.5.1

unknown

[en] Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in Rymera Web Co Wholesale Suite plugin <= 2.1.5 versions.

Affected:
up to 2.1.5.1
Fixed in:
2.1.5.1
Disclosed:
May 9, 2023

CVE-2022-41640 on NVD →

Wholesale Suite <= 2.1.5 - Missing Authorization to Plugin Settings Change

medium

The Wholesale Suite plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the edit_wholesale_role function in versions up to, and including, 2.1.5. This makes it possible for authenticated attackers with subscriber-level privileges to change the plugin's settings.

CVSS:
4.3
Affected:
up to 2.1.5
Fixed in:
2.1.6
Disclosed:
Feb 27, 2023

CVE-2022-34344 on NVD →

Wholesale Suite <= 2.1.5 - Authenticated (Subscriber+) Cross-Site Scripting

medium

The Wholesale Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'role' parameters in versions up to, and including, 2.1.5 due to insufficient input sanitization and output escaping. This makes it possible for subscriber-level, and above, attackers to inject arbitrary web scripts in pages t...

CVSS:
6.4
Affected:
up to 2.1.5
Fixed in:
2.1.5.1
Disclosed:
Nov 28, 2022

CVE-2022-41640 on NVD →

Wholesale Suite <= 2.1.5 - Cross-Site Request Forgery

high

The Wholesale Suite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.5. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to invoke those functions, via forged request granted they can tri...

CVSS:
8.8
Affected:
up to 2.1.5
Fixed in:
2.1.5.1
Disclosed:
Oct 19, 2022

Wholesale Suite – B2B, Dynamic Pricing &amp; WooCommerce Wholesale Prices [woocommerce-wholesale-prices] < 2.1.5.1

unknown

The Wholesale Suite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.5. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to invoke those functions, via forged request granted they can tri...

Affected:
up to 2.1.5.1
Fixed in:
2.1.5.1
Disclosed:
Oct 19, 2022

Wholesale Suite – B2B, Dynamic Pricing &amp; WooCommerce Wholesale Prices [woocommerce-wholesale-prices] < 2.1.5.1

unknown

Update the WordPress Wholesale Suite plugin to the latest available version (at least 2.1.5.1). Dave Jong discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Wholesale Suite Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and othe...

Affected:
up to 2.1.5.1
Fixed in:
2.1.5.1

Wholesale Suite – B2B, Dynamic Pricing &amp; WooCommerce Wholesale Prices [woocommerce-wholesale-prices] < 2.1.5.1

unknown

The plugin does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks.

Affected:
up to 2.1.5.1
Fixed in:
2.1.5.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database