CVE-2025-49077: WordPress Dynamic Pricing and Discount Rules plugin <= 2.2.9 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in ThemeHigh Dynamic Pricing and Discount Rules allows Cross Site Request Forgery.This issue affects Dynamic Pricing and Discount Rules: from n/a through 2.2.9.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in ThemeHigh Dynamic Pricing and Discount Rules discount-and-dynamic-pricing allows Cross Site Request Forgery.This issue affects Dynamic Pricing and Discount Rules: from n/a through <= 2.2.9.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49077?
CVE-2025-49077 is classified as a Cross-Site Request Forgery (CSRF) vulnerability that can lead to unauthorized actions being performed on behalf of users.
How do I fix CVE-2025-49077?
To fix CVE-2025-49077, upgrade the ThemeHigh Dynamic Pricing and Discount Rules plugin to version 2.2.10 or later.
What versions are affected by CVE-2025-49077?
CVE-2025-49077 affects ThemeHigh Dynamic Pricing and Discount Rules versions up to and including 2.2.9.
Is CVE-2025-49077 specific to WordPress?
Yes, CVE-2025-49077 affects the Dynamic Pricing and Discount Rules plugin for WordPress.
What is the impact of exploiting CVE-2025-49077?
Exploiting CVE-2025-49077 allows attackers to perform unauthorized actions on behalf of authenticated users, potentially compromising site security.