What is CVE-2026-59556?
CVE-2026-59556 is an unauthenticated Cross Site Scripting (XSS) vulnerability in the Dynamic Pricing With Discount Rules for WooCommerce plugin, affecting versions <= 4.5.11. This flaw allows a remote attacker to inject and execute arbitrary JavaScript in the context of a victim's browser. Users should update to the latest available version immediately.
Azərbaycanca: CVE-2026-59556, WooCommerce üçün Dynamic Pricing With Discount Rules plagininin 4.5.11 və daha əvvəlki versiyalarında autentifikasiya olunmamış Cross Site Scripting (XSS) zəifliyidir. Bu, uzaqdan hücumçuya təsirə məruz qalan veb səhifədə ixtiyari JavaScript kodu icra etməyə imkan verir. İstifadəçilər dərhal ən son mövcud versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which plugin and versions are affected by CVE-2026-59556?
CVE-2026-59556 is an unauthenticated XSS vulnerability that affects the Dynamic Pricing With Discount Rules for WooCommerce plugin in versions 4.5.11 and earlier.
How can I protect against CVE-2026-59556?
To protect against this vulnerability, you should immediately update the plugin to the latest available version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.