{"error":0,"message":null,"data":{"name":"Discount Rules for WooCommerce","plugin":"woo-discount-rules","link":"https:\/\/wordpress.org\/plugins\/woo-discount-rules\/","latest":"1789635180","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"08e53f658b625327613c52136c37479e3991b3bcb9c17bb911cba7b80b605c9e","name":"Discount Rules for WooCommerce [woo-discount-rules] < 2.2.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"990b5399af40307881e6b85b4657b12b43e1bc31","name":"WordPress Discount Rules for WooCommerce plugin <= 2.2.0 - Multiple Authorization Bypass vulnerabilities","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woo-discount-rules\/vulnerability\/wordpress-discount-rules-for-woocommerce-plugin-2-2-0-multiple-authorization-bypass-vulnerabilities","description":"Multiple Authorization Bypass vulnerabilities found by WordFence in WordPress Discount Rules for WooCommerce plugin (versions <= 2.2.0).","date":"2020-09-17"}],"impact":[]},{"uuid":"7519b65d2cbfa243e240dae8d3bd0183f7d5b3c34d5b436bd3cf644a7140eef8","name":"Discount Rules for WooCommerce [woo-discount-rules] < 2.1.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.1.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"5bee788f2f1ad9616ebfbe47f902f2b0606f8451","name":"WordPress Discount Rules for WooCommerce plugin <= 2.0.2 - Multiple (XSS, SQLi) Vulnerabilities","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woo-discount-rules\/vulnerability\/wordpress-discount-rules-for-woocommerce-plugin-2-0-2-multiple-xss-sqli-vulnerabilities","description":"Multiple (XSS, SQLi) Vulnerabilities found by WebARX Security in WordPress Discount Rules for WooCommerce plugin (versions <= 2.0.2).","date":"2020-08-20"}],"impact":[]},{"uuid":"c75428c0984a798970f0ebf713788bee35e000452f7c1ca49373674ccd3a94a1","name":"Discount Rules for WooCommerce [woo-discount-rules] < 2.4.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-2090","name":"CVE-2022-2090","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-2090","description":"[en] The Discount Rules for WooCommerce WordPress plugin before 2.4.2 does not escape a parameter before outputting it back in an attribute of the plugin's discount rule page, leading to Reflected Cross-Site Scripting","date":"2022-07-17"},{"id":"1b910ed264a886bef5a7279d8e2ea7b4dd32a2e8","name":"WordPress Discount Rules for WooCommerce plugin <= 2.4.1 - Reflected Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woo-discount-rules\/vulnerability\/wordpress-discount-rules-for-woocommerce-plugin-2-4-1-reflected-cross-site-scripting-xss-vulnerability","description":"Reflected Cross-Site Scripting (XSS) vulnerability discovered by ZhongFu Su aka JrXnm (WuHan University) in WordPress Discount Rules for WooCommerce plugin (versions <= 2.4.1).\nUpdate the WordPress Discount Rules for WooCommerce plugin to the latest available version (at least 2.4.2).","date":"2022-06-27"},{"id":"42321032a7da3b82f246e6207e5dc0e2b4fa1c2a","name":"Discount Rules for WooCommerce <= 2.4.1 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woo-discount-rules\/discount-rules-for-woocommerce-241-reflected-cross-site-scripting","description":"The Discount Rules for WooCommerce WordPress plugin before 2.4.2 does not escape a parameter before outputting it back in an attribute of the plugin's discount rule page, leading to Reflected Cross-Site Scripting","date":"2022-06-27"},{"id":"0201f365-7acb-4640-bd3f-7119432f4917","name":"Woo Discount Rules &lt; 2.4.2 - Reflected Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/0201f365-7acb-4640-bd3f-7119432f4917","description":"The plugin does not escape a parameter before outputting it back in an attribute of the plugin&#039;s discount rule page, leading to Reflected Cross-Site Scripting","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"70df3ea01c0bf9a993292524ac3236efa0af09551199a2c89278ee2be813a690","name":"Discount Rules for WooCommerce [woo-discount-rules] < 2.2.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"dd1f0f74b0954a5c679b019fd8ad50b6b808d90d","name":"Discount Rules for WooCommerce <= 2.2.0 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woo-discount-rules\/discount-rules-for-woocommerce-220-missing-authorization","description":"The Discount Rules for WooCommerce plugin for WordPress is vulnerable to missing authorization via several AJAX actions in versions up to, and including, 2.2.0 due to missing capability checks on various functions. This makes it possible for subscriber-level attackers to execute various actions and perform a wide variety of actions such as modifying discount rules.","date":"2020-09-17"}],"impact":[]},{"uuid":"237d66d88195155efcf133de1efa3395cafaecff5c6b64fcd5c363f85bd19ba3","name":"Discount Rules for WooCommerce [woo-discount-rules] < 2.1.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.1.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"3afa8bba204fdae79b323a3f57cd3cd8735c088b","name":"Discount Rules for WooCommerce <= 2.0.2 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woo-discount-rules\/discount-rules-for-woocommerce-202-missing-authorization","description":"The Discount Rules for WooCommerce plugin for WordPress is vulnerable to missing authorization via several AJAX actions in versions up to, and including, 2.0.2 due to missing capability checks on various functions. This makes it possible for subscriber-level attackers to execute various actions and perform a wide variety of actions such as modifying rules and saving configurations.","date":"2020-08-20"},{"id":"CVE-2020-36834","name":"CVE-2020-36834","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-36834","description":"[en] The Discount Rules for WooCommerce plugin for WordPress is vulnerable to missing authorization via several AJAX actions in versions up to, and including, 2.0.2 due to missing capability checks on various functions. This makes it possible for subscriber-level attackers to execute various actions and perform a wide variety of actions such as modifying rules and saving configurations.","date":"2024-10-16"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"l","i":"l","a":"l","score":"6.3","severity":"m","exploitable":"2.8","impact":"3.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:L\/A:L","score":"6.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"low","i":"low","a":"low","exploitable":"2.8","impact":"3.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"1c266cf6e413e1a61fe47b9709d1c05efc047592cca74b2de681237f00c5e96f","name":"Discount Rules for WooCommerce [woo-discount-rules] < 2.1.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.1.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"f9048083-69aa-46d4-823d-1c9a1221513e","name":"Discount Rules for WooCommerce &lt; 2.1.0 - Multiple Vulnerabilities","link":"https:\/\/wpscan.com\/vulnerability\/f9048083-69aa-46d4-823d-1c9a1221513e","description":"The Discount Rules for WooCommerce plugin (versions below 2.1.0) suffers from multiple vulnerabilities such as SQL injection, authorization issues and unauthenticated stored cross-site scripting.\r\n\r\nThe issues in this plugin are caused due to a lack of authorization and nonce token check. The plugin registers several AJAX actions of which one, wp_ajax_wdr_ajax, handles a bulk of different AJAX actions which are supposedly only be accessed by administrators.\r\n\r\nUnfortunately this AJAX action is also registered as wp_ajax_nopriv_wdr_ajax. Even if wp_ajax_nopriv_wdr_ajax was not registered, authenticated users could still exploit this since wp_ajax_wdr_ajax does not perform any type of authorization or CSRF check.\r\n\r\nParticularly the wdr_ajax_save_configuration method that can be executed in this AJAX action can cause significant damage to the site as it allows you to write any type of HTML or JavaScript to any template hook of the site, including wp-admin.","date":null}],"impact":[]},{"uuid":"509db8729ca201984846def952633ea97129e57ceb7c043b9f1bde228457c5ea","name":"Discount Rules for WooCommerce [woo-discount-rules] < 2.2.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"50625e77-3560-4156-8b4a-e43fc0d0c89c","name":"Discount Rules for WooCommerce &lt; 2.2.1 - Multiple Authorization Bypass","link":"https:\/\/wpscan.com\/vulnerability\/50625e77-3560-4156-8b4a-e43fc0d0c89c","description":"On August 20th 2020 WebARX disclosed multiple vulnerabilities affecting the Discount Rules for WooCommerce WordPress plugin, which were patched in version 2.1.0 (see references).\r\n\r\nSome time after, the Wordfence Threat Intelligence Team discovered several additional authorization bypass vulnerabilities affecting the Discount Rules for WooCommerce WordPress plugin.\r\n\r\nThe bypasses could lead to Stored Cross-Site Scripting (XSS).","date":null}],"impact":[]},{"uuid":"8a608f1328928777a4ba6cccd00f5ca9b65433f726682c52672923b54c2eda53","name":"Discount Rules for WooCommerce [woo-discount-rules] < 2.6.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.6.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-8541","name":"CVE-2024-8541","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-8541","description":"[en] The Discount Rules for WooCommerce \u2013 Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.6.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a site administrator into performing an action such as clicking on a link. Please note that this is only exploitable when the 'Leave a Review' notice is present, which occurs after 100 orders are made and disappears after a user dismisses the notice.","date":"2024-10-16"},{"id":"47f32bf1ef828af71c23f34f8ba7ad378ecc78a9","name":"Discount Rules for WooCommerce \u2013 Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons <= 2.6.5 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woo-discount-rules\/discount-rules-for-woocommerce-create-smart-woocommerce-coupons-discounts-bulk-discount-bogo-coupons-265-reflected-cross-site-scripting","description":"The Discount Rules for WooCommerce \u2013 Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.6.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a site administrator into performing an action such as clicking on a link. Please note that this is only exploitable when the 'Leave a Review' notice is present, which occurs after 100 orders are made and disappears after a user dismisses the notice.","date":"2024-10-15"},{"id":"1209efac49c100ec9500f294695e917279aef87e","name":"WordPress Discount Rules for WooCommerce Plugin <= 2.6.5 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woo-discount-rules\/vulnerability\/wordpress-discount-rules-for-woocommerce-plugin-2-6-5-reflected-cross-site-scripting-vulnerability","description":"<p>WordPress Discount Rules for WooCommerce Plugin <= 2.6.5 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Discount Rules for WooCommerce<\/p><p>Link: https:\/\/wordpress.org\/plugins\/woo-discount-rules\/#developers<\/p><p>Affected Version <= 2.6.5<\/p><p>Fixed in version 2.6.6 <\/p>","date":"2024-10-15"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1776153795"}