Access violation vulnerability in Advanced Dynamic Pricing for WooCommerce 4.1.5

The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to malicious changes to its advanced pricing rules. This plugin, used by websites running on WordPress, could be manipulated by an authorized user with at least ‘Subscriber’ level access. The vulnerability exists in versions of the plugin up to 4.1.5, where there is a missing capability check on the migrateCommonToProductOnly function.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.