CVE-2026-13725EPSS p18.8%
CVE-2026-13725CVE-2026-13725
Description
The Dynamic Pricing With Discount Rules for WooCommerce WordPress plugin before 5.0.0 does not validate a nonce or user capabilities on one of its AJAX actions and reflects unsanitised user input in the response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against a victim who is induced to send a crafted request.
Scoring
| CVSS | 7.1 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L |
| EPSS | 0.28% probability of exploitation · percentile 18.8% · 2026-10-05T12:00:23Z |
| Last modified | 2026-08-26 |