Impact
The vulnerability is a missing authorization flaw that permits users to exploit incorrectly configured access control security levels within the Coupon Affiliates plugin. This flaw can allow attackers to access, modify, or delete coupons and related settings without proper privileges, potentially leading to unauthorized data exposure or manipulation. The weakness is classified as CWE‑862, indicating an improper authorization control.
Affected Systems
Vendors affected include Elliot Sowersby and RelyWP, distributor of the Coupon Affiliates (woo‑coupon‑usage) plugin. All releases from the earliest available version up through 6.8.0 are impacted, meaning any WordPress site using a version of the plugin not newer than 6.8.0 is at risk.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity, and the EPSS score is reported as less than 1 %, suggesting a low probability of exploitation at this time. The plugin is used via the WordPress administration interface, so the attack vector is likely through authenticated or unauthenticated HTTP requests to the plugin’s endpoints; this inference is drawn from the plugin nature and typical web‑plugin interactions. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
EUVD