---
id: CVE-2026-13725
title: >-
  The Dynamic Pricing With Discount Rules for WooCommerce WordPress plugin
  before 5.0.0 does not validate a nonce or user capabilities on one of its AJAX
  actions and reflects unsanitised user input in the response, allowing
  unauthenticated…
summary: >-
  The Dynamic Pricing With Discount Rules for WooCommerce WordPress plugin
  before 5.0.0 does not validate a nonce or user capabilities on one of its AJAX
  actions and reflects unsanitised user input in the response, allowing
  unauthenticated…
severity: none
published: '2026-08-01'
updated: '2026-08-01'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-13725'
references:
  - url: 'https://wpscan.com/vulnerability/5e3786de-4b4d-4da2-b129-7b0fef90a386/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00282
epssPercentile: 0.18438
ingestedAt: '2026-08-02T01:16:32.472Z'
---

## Overview

The Dynamic Pricing With Discount Rules for WooCommerce WordPress plugin before 5.0.0 does not validate a nonce or user capabilities on one of its AJAX actions and reflects unsanitised user input in the response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against a victim who is induced to send a crafted request.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
