SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-13725

HIGH · CVSS 7.1 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-08-01 · Last synced 2026-08-31

CyberRota Analysis

AI-Generated

The Dynamic Pricing With Discount Rules for WooCommerce plugin for WordPress prior to version 5.0.0 is vulnerable due to inadequate nonce validation and user capability checks on an AJAX action, which leads to reflected Cross-Site Scripting (XSS). This flaw allows unauthenticated attackers to execute malicious scripts in the context of a victim's session, potentially compromising user data and site integrity. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of exploitation.

CVE
CVE-2026-13725
Severity
HIGH
CVSS
7.1
EPSS
0.16%
WordPress

Original NVD Description

The Dynamic Pricing With Discount Rules for WooCommerce WordPress plugin before 5.0.0 does not validate a nonce or user capabilities on one of its AJAX actions and reflects unsanitised user input in the response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against a victim who is induced to send a crafted request.