CVE-2025-47588: WordPress Dynamic Pricing With Discount Rules for WooCommerce plugin <= 4.5.9 - Arbitrary Code Execution vulnerability
Improper Control of Generation of Code ('Code Injection') vulnerability in acowebs Dynamic Pricing With Discount Rules for WooCommerce aco-woo-dynamic-pricing allows Code Injection.This issue affects Dynamic Pricing With Discount Rules for WooCommerce: from n/a through <= 4.5.9.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47588?
CVE-2025-47588 has a high severity due to its potential for code injection, which can lead to arbitrary code execution.
How do I fix CVE-2025-47588?
To fix CVE-2025-47588, update the Dynamic Pricing With Discount Rules for WooCommerce plugin to version 4.5.10 or later.
What versions of Dynamic Pricing With Discount Rules for WooCommerce are affected by CVE-2025-47588?
CVE-2025-47588 affects versions up to and including 4.5.9 of the Dynamic Pricing With Discount Rules for WooCommerce plugin.
What are the risks associated with CVE-2025-47588?
The risks associated with CVE-2025-47588 include unauthorized code execution, which can compromise website integrity and security.
Is there a way to mitigate CVE-2025-47588 without updating?
Mitigation without updating is limited and not recommended; it's best to upgrade to a secure version to eliminate the vulnerability.