What is CVE-2026-13725?
This vulnerability exists in the Dynamic Pricing With Discount Rules for WooCommerce plugin versions before 5.0.0. It allows unauthenticated attackers to perform Reflected Cross-Site Scripting via an AJAX action due to missing nonce validation and lack of input sanitization. WordPress administrators should update the plugin to version 5.0.0 or later.
Azərbaycanca: Bu zəiflik Dynamic Pricing With Discount Rules for WooCommerce plagininin 5.0.0 versiyasından əvvəlki variantlarında aşkarlanıb. O, autentifikasiyasız hücumçulara AJAX əməliyyatı vasitəsilə Reflected Cross-Site Scripting (XSS) həyata keçirməyə imkan verir, çünki nonce yoxlanışı və sanitizasiya tətbiq edilmir. WordPress adminləri plagini ən azı 5.0.0 versiyasına yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: WooCommerce
FAQ2
Which versions of the Dynamic Pricing With Discount Rules for WooCommerce plugin are affected by CVE-2026-13725?
All versions of the plugin before 5.0.0 are affected by this vulnerability.
Why can an attacker bypass authentication when exploiting CVE-2026-13725?
Because the AJAX action lacks nonce validation and input sanitization, allowing unauthenticated access.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.