Conversation
supportHello, I received following security risk warning: ————————————————————————— Input validation vulnerability in Dynamic Pricing and Discount Rules for WooCommerce 2.4.0 CVE-2023-40559 Severity: medium-risk Status: Open Publication: August 16, 2023 The WooCommerce Dynamic Pricing and Discount Rules plugin for WordPress has a security vulnerability in versions up to and including 2.4.0. This vulnerability is due to a lack of nonce validation on several functions, which means that malicious attackers can control the plugin’s settings by sending a false request, as long as they can trick a site ————————————————————————– I am running Woocomerce v8.0.2, WP6.3. Can you possible to fix it? Thanks in advance!
Hello @cfm168 , Thanks for reaching. We are working on the security points and will release a new version with the security patch. Best Regards, Hitendra & Dotstore Team
Any updates?
Thanks for the followup. The testing is almost finished, and it will be released next week. Best, Hitendra & Dotstore Team
Hello @cfm168 Please update the plugin version to resolve your query. Best Regards, Hitendra & Dotstore Team
I already have the Version 2.4.1. Thanks!
Thanks for the upgrade!
Hello @cfm168 , Thanks for reaching. We are working on the security points and will release a new version with the security patch. Best Regards, Hitendra & Dotstore Team
Any updates?
Thanks for the followup. The testing is almost finished, and it will be released next week. Best, Hitendra & Dotstore Team
Hello @cfm168 Please update the plugin version to resolve your query. Best Regards, Hitendra & Dotstore Team
I already have the Version 2.4.1. Thanks!
Thanks for the upgrade!