Description
The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the apmswn_create_discount() function in all versions up to, and including, 2.8.0. This makes it possible for unauthenticated attackers to create coupons.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-4815 | The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the apmswn_create_discount() function in all versions up to, and including, 2.8.0. This makes it possible for unauthenticated attackers to create coupons. |
References
History
Fri, 01 Aug 2025 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Akashmalik scratch \& Win
|
|
| CPEs | cpe:2.3:a:akashmalik:scratch_\&_win:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Akashmalik scracth \& Win
|
Akashmalik scratch \& Win
|
Fri, 21 Feb 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Akashmalik
Akashmalik scracth \& Win |
|
| CPEs | cpe:2.3:a:akashmalik:scracth_\&_win:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Akashmalik
Akashmalik scracth \& Win |
Tue, 18 Feb 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Feb 2025 08:30:00 +0000
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:09:59.666Z
Reserved: 2025-01-09T22:05:47.683Z
Link: CVE-2024-13316
Updated: 2025-02-18T14:34:21.483Z
Status : Analyzed
Published: 2025-02-18T09:15:09.400
Modified: 2025-08-01T02:06:31.680
Link: CVE-2024-13316
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD