Description
The WooCommerce Smart Coupons plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the woocommerce_coupon_admin_init function in versions up to, and including, 4.6.0. This makes it possible for unauthenticated attackers to send themselves gift certificates of any value, which could be redeemed for products sold on the victim’s storefront.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-30793 | The WooCommerce Smart Coupons plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the woocommerce_coupon_admin_init function in versions up to, and including, 4.6.0. This makes it possible for unauthenticated attackers to send themselves gift certificates of any value, which could be redeemed for products sold on the victim’s storefront. |
References
History
Wed, 16 Oct 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Woocommerce
Woocommerce woocommerce Smart Coupons |
|
| CPEs | cpe:2.3:a:woocommerce:woocommerce_smart_coupons:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Woocommerce
Woocommerce woocommerce Smart Coupons |
|
| Metrics |
ssvc
|
Wed, 16 Oct 2024 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WooCommerce Smart Coupons plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the woocommerce_coupon_admin_init function in versions up to, and including, 4.6.0. This makes it possible for unauthenticated attackers to send themselves gift certificates of any value, which could be redeemed for products sold on the victim’s storefront. | |
| Title | WooCommerce Smart Coupons <= 4.6.0 - Unauthenticated Coupon Creation | |
| Weaknesses | CWE-285 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:31:51.771Z
Reserved: 2024-10-15T18:51:09.627Z
Link: CVE-2020-36841
Updated: 2024-10-16T17:07:20.683Z
Status : Awaiting Analysis
Published: 2024-10-16T13:15:11.733
Modified: 2024-10-16T16:38:14.557
Link: CVE-2020-36841
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD