Executive brief
Advanced Coupons for WooCommerce is a WordPress plugin used to manage promotional offers and discounts for online stores. A security vulnerability in this plugin could allow an attacker with low-level access to inject malicious scripts into the website. If a site administrator or customer interacts with the affected area, the attacker could potentially redirect users to malicious sites, display unauthorized advertisements, or steal session information.
Technical details
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the Advanced Coupons for WooCommerce Coupons plugin (advanced-coupons-for-woocommerce-free) due to improper neutralization of input during web page generation. The flaw allows an authenticated attacker with 'Contributor' level privileges to inject malicious scripts that execute in the context of a victim's browser. Successful exploitation requires user interaction, such as a privileged user clicking a crafted link or visiting a specific page. This can lead to unauthorized script execution, session hijacking, or website defacement. The issue is addressed in version 4.7.2.
Affected products
- Josh Kohlbach / Rymera Web Co Advanced Coupons for WooCommerce Coupons <= 4.7.1.1
Timeline
- 2026-02-26: disclosed: Vulnerability reported by researcher timomangcut
- 2026-03-28: advisory: Patchstack published advisory and assigned PSID 0c1c19194b58
- 2026-04-08: advisory: CVE-2026-39508 published to NVD
- 2026-04-08: patched: Fixed in version 4.7.2