CyberRota
← Ana sayfaya dön

CVE-2026-13725

UNKNOWN · CVSS N/A

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-08-01T07:16:29.560 · Çekilme zamanı: 2026-08-01T12:06:04.815330+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

CVE
CVE-2026-13725
Severity
UNKNOWN
CVSS
N/A
EPSS
Yok
WordPress

Orijinal NVD Açıklaması

The Dynamic Pricing With Discount Rules for WooCommerce WordPress plugin before 5.0.0 does not validate a nonce or user capabilities on one of its AJAX actions and reflects unsanitised user input in the response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against a victim who is induced to send a crafted request.