Executive brief
A security flaw exists in the Smart Coupons for WooCommerce plugin, which is used by online stores to manage gift cards and promotional discounts. An unauthorized person could exploit this issue to bypass security checks and perform actions they should not be allowed to do, potentially altering coupon settings or store data. This could lead to financial loss or unauthorized discounts being applied to orders.
Technical details
The Smart Coupons for WooCommerce plugin for WordPress is vulnerable to broken access control (CWE-862) in versions prior to 2.3.0. The vulnerability stems from a lack of proper authorization checks on certain functions, allowing an unauthenticated remote attacker to execute actions that should be restricted to higher-privileged users. According to the CVSS vector, the impact is primarily on integrity, suggesting that an attacker could modify data or settings without authorization. The issue is resolved in version 2.3.0.
Affected products
- WebToffee Smart Coupons for WooCommerce before 2.3.0
Timeline
- 2026-04-22: other: Reported by researcher hhhai
- 2026-05-15: patched: Patch released in version 2.3.0
- 2026-05-25: disclosed: Public disclosure of CVE-2026-45438