WooCommerce Dynamic Pricing and Discounts <= 2.4.1 - Unauthenticated Settings Import/Export

2021-08-31 00:00
Jerome Bruandet

Strategic Overview

Status
Patched in 2.4.2
Affected Version< 2.4.2
CVSS5.3Medium
CVECVE-2021-4353
View all WooCommerce Dynamic Pricing and Discounts vulnerabilities

Vulnerability Overview

The WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to unauthenticated settings export in versions up to, and including, 2.4.1. This is due to missing authorization on the export() function which makes makes it possible for unauthenticated attackers to export the plugin's settings.

Technical Analysis

REMEDIATION: Update to version 2.4.2, or a newer patched version --- IDENTIFIER: CWE-288 (Authentication Bypass Using an Alternate Path or Channel) The product requires authentication, but the product has an alternate path or channel that does not require authentication.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C