Input validation vulnerability in Premmerce Wholesale Pricing for WooCommerce 1.1.10

The Premmerce Wholesale Pricing for WooCommerce plugin for WordPress has a security vulnerability that allows hackers to access sensitive information and modify display names in the database. This can be done through the ‘ID’ and ‘price_type’ parameters, which are not properly secured. This vulnerability affects versions 1.1.10 and below. Attackers with subscriber level access or higher can exploit this vulnerability to manipulate SQL queries and cause cosmetic damage to the admin interface.

Detected in:

Premmerce Wholesale Pricing for WooCommerce open vulnerable versions: >= * <= 1.1.10

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.