CyberRota Analysis
AI-GeneratedThe Dynamic Pricing With Discount Rules for WooCommerce plugin for WordPress prior to version 5.0.0 is vulnerable due to inadequate nonce validation and user capability checks on an AJAX action, which leads to reflected Cross-Site Scripting (XSS). This flaw allows unauthenticated attackers to execute malicious scripts in the context of a victim's session, potentially compromising user data and site integrity. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of exploitation.
Original NVD Description
The Dynamic Pricing With Discount Rules for WooCommerce WordPress plugin before 5.0.0 does not validate a nonce or user capabilities on one of its AJAX actions and reflects unsanitised user input in the response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against a victim who is induced to send a crafted request.