Impact
The vulnerability is a missing authorization flaw that permits attackers to exploit incorrect access‑control settings within the WP Coupons and Deals plugin. By bypassing normal permission checks, a malicious user could access administrative functions, alter or delete coupon data, and potentially gain a foothold for further compromise. This weakness aligns with CWE‑862, indicating that the plugin fails to enforce proper authorization.
Affected Systems
Affected systems are WordPress installations running the WP Coupons and Deals plugin version 3.2.4 or earlier. The vendor, Imtiaz Rayhan, verifies that the flaw exists in all releases up to and including 3.2.4.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, but the EPSS score of less than 1 percent suggests a very low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, implying that no widespread exploits have been reported. Likely attack vectors involve interacting with the plugin’s web interface or manipulating URLs to invoke privileged actions, assuming insufficient permission checks.
OpenCVE Enrichment