AcoWebs Dynamic Pricing With Discount Rules for WooCommerce Code Injection Vulnerability

Vulnerability

A code injection vulnerability has been identified in the AcoWebs Dynamic Pricing With Discount Rules for WooCommerce plugin, specifically in versions through 4.5.9. This vulnerability allows for improper control over code generation, enabling malicious users to inject and execute arbitrary code.

Impact

Exploitation of this vulnerability could lead to arbitrary code execution on the affected WordPress site.

Added: Nov 6, 2025, 6:01 PM
Updated: Nov 6, 2025, 9:35 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
10.0
exploitability
7.6
remediation
0.0
relevance
1.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.