Extension WordPress
Vulnérabilités Advanced Dynamic Pricing and Discount Rules for WooCommerce
Cette page rassemble les failles publiées pour Advanced Dynamic Pricing and Discount Rules for WooCommerce, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Advanced Dynamic Pricing and Discount Rules for WooCommerce
13 fiches
Advanced Dynamic Pricing for WooCommerce <= 4.9.3 – Cross-Site Request Forgery to Settings Update
The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.9.3. This is due to missing or incorrect nonce validation on a function. This makes it…
*-4.9.3
4.9.5
17/04/2025
Advanced Dynamic Pricing for WooCommerce <= 4.9.0 – Reflected Cross-Site Scripting
The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 4.9.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
*-4.9.0
4.9.1
05/01/2025
Advanced Dynamic Pricing for WooCommerce <= 4.1.5 – Missing Authorization in ajaxCalculateSeveralProducts function
The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajaxCalculateSeveralProducts function in versions up to, and including, 4.1.5. This makes it possible for…
*-4.1.5
4.1.6
17/02/2023
Advanced Dynamic Pricing for WooCommerce <= 4.1.5 – Missing Authorization in migrateCommonToProductOnly function
The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the migrateCommonToProductOnly function in versions up to, and including, 4.1.5. This makes it possible for…
*-4.1.5
4.1.6
17/02/2023
Advanced Dynamic Pricing for WooCommerce <= 4.1.5 – Missing Authorization in migrateProductOnlyToCommon function
The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the migrateProductOnlyToCommon function in versions up to, and including, 4.1.5. This makes it possible for…
*-4.1.5
4.1.6
17/02/2023
Advanced Dynamic Pricing for WooCommerce <= 4.1.5 – Cross-Site Request Forgery via migrateProductOnlyToCommon function
The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.5. This is due to missing or incorrect nonce validation on the migrateProductOnlyToCommon function. This makes it…
*-4.1.5
4.1.6
17/02/2023
Advanced Dynamic Pricing for WooCommerce <= 4.1.5 – Cross-Site Request Forgery via handleSubmitAction function
The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.5. This is due to missing or incorrect nonce validation on the handleSubmitAction function. This makes it…
*-4.1.5
4.1.6
17/02/2023
Advanced Dynamic Pricing for WooCommerce <= 4.1.5 – Missing Authorization in ajaxCalculatePrice function
The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajaxCalculatePrice function in versions up to, and including, 4.1.5. This makes it possible for…
*-4.1.5
4.1.6
17/02/2023
Advanced Dynamic Pricing for WooCommerce <= 4.1.5 – Cross-Site Request Forgery via migrateCommonToProductOnly function
The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.5. This is due to missing or incorrect nonce validation on the migrateCommonToProductOnly function. This makes it…
*-4.1.5
4.1.6
17/02/2023
Advanced Dynamic Pricing for WooCommerce <= 4.1.5 – Cross-Site Request Forgery
The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.5. This is due to missing or incorrect nonce validation on several functions related to data migration.…
*-4.1.5
4.1.6
30/10/2022
Advanced Dynamic Pricing for WooCommerce <= 4.1.5 – Cross-Site Request Forgery
The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.5. This is due to missing or incorrect nonce validation on several functions such as exportCSVBulkRangesAjaxCB(). This…
*-4.1.5
4.1.6
26/10/2022
Advanced Dynamic Pricing for WooCommerce <= 4.1.5 – Missing Authorization
The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing access control on the exportCSVBulkRangesAjaxCB() function, in addition to several other functions, in versions up to, and including, 4.1.5. This…
*-4.1.5
4.1.6
25/10/2022
Advanced Dynamic Pricing for WooCommerce <= 4.1.3 – Cross-Site Request Forgery to Plugin Settings Update
The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.3. This is due to missing or incorrect nonce validation on the handleSubmitAction function. This makes it…
*-4.1.3
4.1.4
12/09/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.