Executive brief
Couponer for Elementor is a WordPress plugin that integrates coupon functionality with the Elementor page builder. A broken access control vulnerability in this plugin allows authenticated users (those with subscriber privileges or higher) to access pages and perform actions they should not be authorized to perform, such as viewing other users' data or manipulating coupons. This could lead to unauthorized data exposure and business logic bypass on affected websites.
Technical details
The vulnerability is a broken access control flaw (CWE-639) affecting Couponer for Elementor through version 1.1.7. The plugin fails to properly validate user permissions before allowing access to sensitive functionality, allowing authenticated users with subscriber-level privileges to bypass authorization checks. The attack vector is network-based and requires valid user authentication. An attacker with subscriber credentials can exploit this to access restricted pages or perform unauthorized actions. As of the advisory publication date, no official patch is available from the vendor.
Affected products
- merkulove Couponer for Elementor through 1.1.7
Timeline
- 2025-11-10: disclosed: Vulnerability reported to Patchstack by Phat RiO
- 2025-12-31: advisory: Published by Patchstack and CVE-2025-66154 assigned