{"error":0,"message":null,"data":{"name":"Wholesale Suite \u2013 B2B, Dynamic Pricing &amp; WooCommerce Wholesale Prices","plugin":"woocommerce-wholesale-prices","link":"https:\/\/wordpress.org\/plugins\/woocommerce-wholesale-prices\/","latest":"1785718800","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"28389df0ff8d76c868c72c98e7f8806a68346f8f77170014df49a8b99afecf9e","name":"Wholesale Suite \u2013 B2B, Dynamic Pricing &amp; WooCommerce Wholesale Prices [woocommerce-wholesale-prices] < 2.1.5.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.1.5.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"52d60d940aeadf2db4ad84ad458f877983f7b389","name":"WordPress Wholesale Suite Plugin <= 2.1.5 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce-wholesale-prices\/vulnerability\/wordpress-wholesale-suite-plugin-2-1-5-authenticated-cross-site-scripting-xss-vulnerability","description":"Update the WordPress Wholesale Suite plugin to the latest available version (at least 2.1.5.1).\nDave Jong discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Wholesale Suite Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 2.1.5.1.","date":null}],"impact":[]},{"uuid":"63faae349e5363606f82dc5423eaca5850e2ba8e27c2588cfff60c95ccc0976f","name":"Wholesale Suite \u2013 B2B, Dynamic Pricing &amp; WooCommerce Wholesale Prices [woocommerce-wholesale-prices] < 2.1.5.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.1.5.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-41640","name":"CVE-2022-41640","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-41640","description":"[en] Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in Rymera Web Co Wholesale Suite plugin <=\u00a02.1.5 versions.","date":"2023-05-09"},{"id":"9a702383985d9a97e8bb9bb34b1fe97c9598731f","name":"Wholesale Suite <= 2.1.5 - Authenticated (Subscriber+) Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce-wholesale-prices\/wholesale-suite-215-authenticated-subscriber-cross-site-scripting","description":"The Wholesale Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'role' parameters in versions up to, and including, 2.1.5 due to insufficient input sanitization and output escaping. This makes it possible for subscriber-level, and above, attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2022-11-28"},{"id":"06334862-0d91-4272-9dc8-8ff3dc14aa97","name":"Wholesale Suite &lt; 2.1.5.1 - Subscriber+ Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/06334862-0d91-4272-9dc8-8ff3dc14aa97","description":"The plugin does not sanitise and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"6.5","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"e8c8b1ea1c7a654e4ed881c9ea83bcfeca280c7def83ecd4c1bc81734b0d4647","name":"Wholesale Suite \u2013 B2B, Dynamic Pricing &amp; WooCommerce Wholesale Prices [woocommerce-wholesale-prices] < 2.1.5.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.1.5.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"18d164138f7ef9dae2fbadedbc60e0404fb8c6cd","name":"Wholesale Suite <= 2.1.5 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce-wholesale-prices\/wholesale-suite-215-cross-site-request-forgery","description":"The Wholesale Suite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.5. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to invoke those functions, via forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2022-10-19"}],"impact":[]},{"uuid":"704c440e18031f84ef14e62a4e61d72c2c1d3b7600899785d3cee39f39e4cf53","name":"Wholesale Suite \u2013 B2B, Dynamic Pricing &amp; WooCommerce Wholesale Prices [woocommerce-wholesale-prices] < 2.1.5.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.1.5.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-34344","name":"CVE-2022-34344","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-34344","description":"[en] Missing Authorization vulnerability in Rymera Web Co Wholesale Suite \u2013 WooCommerce Wholesale Prices, B2B, Catalog Mode, Order Form, Wholesale User Roles, Dynamic Pricing & More.This issue affects Wholesale Suite \u2013 WooCommerce Wholesale Prices, B2B, Catalog Mode, Order Form, Wholesale User Roles, Dynamic Pricing & More: from n\/a through 2.1.5.","date":"2024-01-08"},{"id":"af314201442b61d33a12270513e3278e40243d16","name":"Wholesale Suite <= 2.1.5 - Missing Authorization to Plugin Settings Change","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce-wholesale-prices\/wholesale-suite-215-missing-authorization-to-plugin-settings-change","description":"The Wholesale Suite plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the edit_wholesale_role function in versions up to, and including, 2.1.5. This makes it possible for authenticated attackers with subscriber-level privileges to change the plugin's settings.","date":"2023-02-27"},{"id":"7a944c60242e627dc891af3b5f54e0e612eda0ec","name":"WordPress  Wholesale Suite Plugin  <= 2.1.5 is vulnerable to Settings Change","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce-wholesale-prices\/vulnerability\/wordpress-wholesale-suite-plugin-2-1-5-auth-plugin-settings-change-vulnerability","description":"Update the WordPress Wholesale Suite plugin to the latest available version (at least 2.1.5.1).\nDave Jong (Patchstack) discovered and reported this Settings Change vulnerability in WordPress Wholesale Suite Plugin.  This vulnerability has been fixed in version 2.1.5.1.","date":"2023-02-27"},{"id":"ae15f7ff-3c3f-4531-a042-aec85f4a50c7","name":"Wholesale Suite &lt; 2.1.5.1 - Subscriber+ Missing Authorization for Plugin Settings Change","link":"https:\/\/wpscan.com\/vulnerability\/ae15f7ff-3c3f-4531-a042-aec85f4a50c7","description":"The plugin does not adequately authorize settings changes, allowing users with a role as low as Subscriber to update plugin settings.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"l","score":"5.4","severity":"m","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:L","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"low","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"89da2c1041754988c02ef19eb9af35787d55a9381ea28edb7fe3f26540f801cf","name":"Wholesale Suite \u2013 B2B, Dynamic Pricing &amp; WooCommerce Wholesale Prices [woocommerce-wholesale-prices] < 2.1.5.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.1.5.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"f087eb3d-a124-4311-bfc0-9b11b9df0cf0","name":"Wholesale Suite &lt; 2.1.5.1 - Cross-Site Request Forgery","link":"https:\/\/wpscan.com\/vulnerability\/f087eb3d-a124-4311-bfc0-9b11b9df0cf0","description":"The plugin does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks.","date":null}],"impact":[]},{"uuid":"8b7c1c95f3b23f4bbd01e0aeea043f468639a965beb1225b5958d06645e07fe2","name":"Wholesale Suite \u2013 B2B, Dynamic Pricing &amp; WooCommerce Wholesale Prices [woocommerce-wholesale-prices] < 2.2.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-38745","name":"CVE-2024-38745","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-38745","description":"[en] Missing Authorization vulnerability in Rymera Web Co Wholesale Suite allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Wholesale Suite: from n\/a through 2.1.12.","date":"2024-11-01"},{"id":"47c626fd9d3c0e7f30a25631e287408665edc894","name":"WordPress Wholesale Suite Plugin <= 2.1.12 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/woocommerce-wholesale-prices\/vulnerability\/wordpress-wholesale-suite-plugin-2-1-12-broken-access-control-vulnerability","description":"<p>WordPress Wholesale Suite Plugin <= 2.1.12 is vulnerable to Broken Access Control<\/p><p>Software: Wholesale Suite<\/p><p>Link: https:\/\/wordpress.org\/plugins\/woocommerce-wholesale-prices\/#developers<\/p><p>Affected Version <= 2.1.12<\/p><p>Fixed in version 2.2.0 <\/p>","date":"2024-07-11"},{"id":"5cfbea1b74b8955042bbf09900a58091f279590b","name":"Wholesale Suite <= 2.1.12 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce-wholesale-prices\/wholesale-suite-2112-missing-authorization","description":"The Wholesale Suite \u2013 WooCommerce Wholesale Prices, B2B, Catalog Mode, Order Form, Wholesale User Roles, Dynamic Pricing & More plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.1.12. This makes it possible for unauthenticated attackers to perform an unauthorized action.","date":"2024-07-11"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"d7207fe3b1e29c95e5bfd125a2ecb96a1a5f21a65e0cf063ce786dc8a0573bd3","name":"Wholesale Suite \u2013 B2B, Dynamic Pricing &amp; WooCommerce Wholesale Prices [woocommerce-wholesale-prices] < 2.2.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-49924","name":"CVE-2025-49924","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-49924","description":"[en] Incorrect Privilege Assignment vulnerability in Josh Kohlbach Wholesale Suite woocommerce-wholesale-prices allows Privilege Escalation.This issue affects Wholesale Suite: from n\/a through <= 2.2.4.2.","date":"2025-10-22"},{"id":"9751095766facdd690674f192ba529426e593497","name":"Wholesale Suite <= 2.2.4.2 - Authenticated (Shop Manager+) Privilege Escalation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce-wholesale-prices\/wholesale-suite-2242-authenticated-shop-manager-privilege-escalation","description":"The Wholesale Suite \u2013 B2B, Dynamic Pricing & Wholesale Prices for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.2.4.2. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to gain administrative-level access.","date":"2025-07-23"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"7.2","severity":"h","exploitable":"3.9","impact":"3.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"7.2","severity":"high","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"3.4"},"cwe":[{"cwe":"CWE-266","name":"Incorrect Privilege Assignment","description":"A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"a8d4edc74400bf675681abcac88dd36753db7aba3d3e49d0ee62f79e4733727c","name":"Wholesale Suite \u2013 B2B, Dynamic Pricing &amp; WooCommerce Wholesale Prices [woocommerce-wholesale-prices] < 2.2.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-27541","name":"CVE-2026-27541","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-27541","description":"[en] Incorrect Privilege Assignment vulnerability in Josh Kohlbach Wholesale Suite woocommerce-wholesale-prices allows Privilege Escalation.This issue affects Wholesale Suite: from n\/a through <= 2.2.6.","date":"2026-03-05"},{"id":"5f9a240d07d72c95c2a7e46998c532a66e486f7b","name":"Wholesale Suite <= 2.2.6 - Authenticated (Shop Manager) Privilege Escalation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/woocommerce-wholesale-prices\/wholesale-suite-221-authenticated-shop-manager-privilege-escalation","description":"The Wholesale Suite \u2013 B2B, Dynamic Pricing & WooCommerce Wholesale Prices plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.2.6.This makes it possible for authenticated attackers, with Shop Manager-level access and above, to elevate their privileges to that of an administrator.","date":"2026-02-20"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"7.2","severity":"h","exploitable":"1.6","impact":"5.5"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"7.2","severity":"high","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"1.6","impact":"5.5"},"cwe":[{"cwe":"CWE-266","name":"Incorrect Privilege Assignment","description":"A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1776441577"}