Impact
The vulnerability is a missing authorization flaw in the Couponer for Elementor plugin. It allows users who should not have privileged access to view or alter coupon configurations and potentially other administrative functions. The weakness, identified as CWE‑862, results in a breach of the principle of least privilege and can lead to unauthorized data exposure or manipulation.
Affected Systems
WordPress sites that have installed the merkulove Couponer for Elementor plugin with a version up to and including 1.1.7 are impacted. No specific sub‑version range beyond the upper bound is mentioned. Sites using newer versions are assumed to be unaffected.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate impact, while the EPSS score of less than 1% shows a low likelihood of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires network or web access to the WordPress installation and can be performed by authenticated or unauthenticated users depending on the existing role configuration. The likely attack vector is web‑based through the plugin’s public endpoints.
OpenCVE Enrichment