Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Josh Kohlbach Advanced Coupons for WooCommerce Coupons advanced-coupons-for-woocommerce-free.This issue affects Advanced Coupons for WooCommerce Coupons: from n/a through <= 4.6.8.
Published: 2025-10-22
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Advanced Coupons for WooCommerce Coupons plugin contains an SQL injection flaw that permits an attacker to submit crafted input that is incorporated directly into a database query without sufficient escaping or parameterization. Based on the description, it is inferred that this flaw could enable the attacker to read, modify, or delete data in the WordPress database, potentially exposing user credentials and sensitive business information. The weakness is identified as CWE-89.

Affected Systems

Any WordPress site that has the Advanced Coupons for WooCommerce Coupons plugin from its first release up through version 4.6.8 is vulnerable. The plugin, developed by Josh Kohlbach, is presumed to process user input on coupon and configuration pages, which provides a reachable attack surface for malicious actors.

Risk and Exploitability

The CVSS base score of 7.6 denotes a high severity risk, while the EPSS score of less than 1 % indicates that current exploitation activity is low but not impossible. The vulnerability is not listed in CISA's KEV catalog, yet its potential for data theft or unauthorized database manipulation remains substantial. Based on the description, it is inferred that exploitation would likely involve submitting malicious payloads through the plugin’s administrative interfaces, particularly if the database user runs with elevated privileges or if the application lacks additional input filtering.

Generated by OpenCVE AI on April 30, 2026 at 05:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Advanced Coupons for WooCommerce Coupons plugin to the latest release that contains the SQL injection patch.
  • If an immediate upgrade is not feasible, disable the Advanced Coupons for WooCommerce Coupons plugin to remove the vulnerable functionality.
  • Configure the database user used by WordPress with the minimum privileges required for normal operation to limit the impact of any successful injection.
  • Deploy a Web Application Firewall or implement security rules that filter common SQL injection patterns against the plugin’s endpoints.

Generated by OpenCVE AI on April 30, 2026 at 05:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N'}

cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Fri, 24 Oct 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Oct 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Josh Kohlbach
Josh Kohlbach advanced Coupons For Woocommerce Coupons
Woocommerce
Woocommerce woocommerce
Woocommerce woocommerce Smart Coupons
Wordpress
Wordpress wordpress
Vendors & Products Josh Kohlbach
Josh Kohlbach advanced Coupons For Woocommerce Coupons
Woocommerce
Woocommerce woocommerce
Woocommerce woocommerce Smart Coupons
Wordpress
Wordpress wordpress

Wed, 22 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Josh Kohlbach Advanced Coupons for WooCommerce Coupons advanced-coupons-for-woocommerce-free.This issue affects Advanced Coupons for WooCommerce Coupons: from n/a through <= 4.6.8.
Title WordPress Advanced Coupons for WooCommerce Coupons plugin <= 4.6.8 - SQL Injection vulnerability
Weaknesses CWE-89
References

Subscriptions

Josh Kohlbach Advanced Coupons For Woocommerce Coupons
Woocommerce Woocommerce Woocommerce Smart Coupons
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:58.949Z

Reserved: 2025-10-07T15:34:13.976Z

Link: CVE-2025-62015

cve-icon Vulnrichment

Updated: 2025-10-24T12:41:06.625Z

cve-icon NVD

Status : Deferred

Published: 2025-10-22T15:16:03.040

Modified: 2026-04-27T17:16:29.717

Link: CVE-2025-62015

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T05:30:06Z

Weaknesses