Junglewise Threat Intelligence

CVE-2026-40770: RelyWP Coupon Affiliates unauthenticated XSS

CVE-2026-40770 · Severity: high · CVSS 7.1 · Published 2026-06-15

Vendors: RelyWP.

Executive brief

The Coupon Affiliates plugin for WordPress, which helps businesses manage affiliate marketing and discount programs, contains a security flaw that allows attackers to inject malicious scripts into the website. If a site administrator or visitor interacts with a specially crafted link, the attacker could potentially hijack sessions, redirect users to malicious sites, or deface the website. This vulnerability can be exploited by anyone on the internet without needing an account on the affected site.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the Coupon Affiliates plugin for WordPress (versions 7.5.3 and below) due to improper neutralization of input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to inject arbitrary JavaScript into the application. Successful exploitation requires a victim (typically a site administrator) to perform an action, such as clicking a malicious link or visiting a crafted page. This can lead to the execution of malicious scripts in the context of the victim's browser session, potentially resulting in session hijacking or unauthorized administrative actions. The issue is resolved in version 7.6.0.

Affected products

  • RelyWP Coupon Affiliates <= 7.5.3

Timeline

  • 2026-03-07: other: Reported by Nguyen Ba Khanh
  • 2026-04-21: advisory: Initial advisory published by Patchstack
  • 2026-06-15: disclosed: CVE published to NVD
  • 2026-04-21: patched: Version 7.6.0 released to address the vulnerability

References

Related threats