Description
Incorrect Privilege Assignment vulnerability in pebas CouponXxL couponxxl allows Privilege Escalation.This issue affects CouponXxL: from n/a through <= 3.0.0.
Published: 2025-10-22
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The CouponXxL WordPress theme contains an Incorrect Privilege Assignment flaw that permits a user with ability to modify theme settings to elevate privileges and gain administrative control over the site. This flaw is a classic Missing Authorization issue (CWE‑266), allowing attackers to create or modify user accounts, change critical settings, or execute arbitrary code at higher privilege levels. The resulting privilege escalation can lead to full site takeover, data exfiltration, or injection of malicious content.

Affected Systems

Versions of the pebas CouponXxL theme from its earliest release up through 3.0.0 are affected. WordPress sites that have installed this theme prior to these releases are at risk. No specific WordPress core version is mentioned, so any WordPress installation using CouponXxL 3.0.0 or older may be vulnerable.

Risk and Exploitability

The CVSS score of 9.8 classifies this issue as Critical. The EPSS score of less than 1% indicates that, at the time of this analysis, exploit activity in the wild is expected to be very low. It is not yet listed in the CISA KEV catalog, so no known wide‑scale exploitation has been reported. Nonetheless, the severity and the obvious privilege escalation potential warrant immediate remediation, as an attacker could exploit this weakness when they obtain any authenticated access to the WordPress back‑end or theme management interface.

Generated by OpenCVE AI on April 29, 2026 at 14:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade CouponXxL theme to a version newer than 3.0.0.
  • If upgrading is not possible, remove or disable the CouponXxL theme to eliminate the vulnerability.
  • Review user roles and recent activity to detect and respond to potential privilege escalations.

Generated by OpenCVE AI on April 29, 2026 at 14:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Thu, 23 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 23 Oct 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Wed, 22 Oct 2025 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Wed, 22 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
Description Incorrect Privilege Assignment vulnerability in pebas CouponXxL couponxxl allows Privilege Escalation.This issue affects CouponXxL: from n/a through <= 3.0.0.
Title WordPress CouponXxL theme <= 3.0.0 - Privilege Escalation vulnerability
Weaknesses CWE-266
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T18:42:14.027Z

Reserved: 2025-09-25T15:34:33.694Z

Link: CVE-2025-60220

cve-icon Vulnrichment

Updated: 2025-10-22T20:35:53.321Z

cve-icon NVD

Status : Deferred

Published: 2025-10-22T15:15:59.107

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-60220

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T14:15:14Z

Weaknesses