Description
Missing Authorization vulnerability in Elliot Sowersby / RelyWP Coupon Affiliates woo-coupon-usage allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Coupon Affiliates: from n/a through <= 6.4.0.
Published: 2025-08-20
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Elliot Sowersby / RelyWP Coupon Affiliates contains a Missing Authorization flaw that permits attackers to alter crucial configuration options. The vulnerability arises from incorrectly defined access control levels, which can allow a user with inadequate privileges to modify settings. Such changes can compromise the intended functionality of the plugin or weaken security controls, thereby affecting the confidentiality and integrity of website operations.

Affected Systems

The Elliot Sowersby / RelyWP Coupon Affiliates plugin version 6.4.0 and earlier are affected. Systems running these outdated releases on WordPress sites should be considered vulnerable. No specific implementations beyond the standard licensed plugin are indicated.

Risk and Exploitability

The CVSS score of 6.5 indicates medium severity. The EPSS score of less than 1% suggests a low probability of exploitation in the wild, and the issue is not listed in the CISA KEV catalog. Nonetheless, attackers could exploit this flaw by leveraging a WordPress account with insufficient privileges; the required attack vector is inferred to be authenticated within the WordPress administrative interface.

Generated by OpenCVE AI on May 1, 2026 at 06:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any official patch or update provided by the vendor, if available.
  • Ensure that WordPress roles and capabilities follow the least‑privilege principle, removing any unnecessary access to the plugin’s settings.
  • Audit existing site users to confirm that only trusted accounts possess administrative or plugin‑configuration rights.

Generated by OpenCVE AI on May 1, 2026 at 06:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-28549 Missing Authorization vulnerability in Elliot Sowersby / RelyWP Coupon Affiliates allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Coupon Affiliates: from n/a through 6.4.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Elliot Sowersby / RelyWP Coupon Affiliates allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Coupon Affiliates: from n/a through 6.4.0. Missing Authorization vulnerability in Elliot Sowersby / RelyWP Coupon Affiliates woo-coupon-usage allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Coupon Affiliates: from n/a through <= 6.4.0.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Sun, 24 Aug 2025 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Relywp
Relywp coupon Affiliates
Wordpress
Wordpress wordpress
Vendors & Products Relywp
Relywp coupon Affiliates
Wordpress
Wordpress wordpress

Wed, 20 Aug 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 20 Aug 2025 08:15:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Elliot Sowersby / RelyWP Coupon Affiliates allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Coupon Affiliates: from n/a through 6.4.0.
Title WordPress Coupon Affiliates Plugin <= 6.4.0 - Settings Change Vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Relywp Coupon Affiliates
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:28.978Z

Reserved: 2025-07-16T08:51:50.628Z

Link: CVE-2025-54025

cve-icon Vulnrichment

Updated: 2025-08-20T13:55:28.788Z

cve-icon NVD

Status : Deferred

Published: 2025-08-20T08:15:46.207

Modified: 2026-04-23T15:32:43.447

Link: CVE-2025-54025

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T06:45:11Z

Weaknesses