Executive brief
The Coupon Affiliates plugin for WordPress, which helps businesses manage affiliate marketing and discount codes, contains a security flaw that exposes sensitive information. This vulnerability allows unauthorized individuals to access data that should be restricted to administrators or specific users. Such exposure could lead to the loss of private business data or provide attackers with information needed to launch further attacks against the website.
Technical details
A sensitive data exposure vulnerability exists in the Coupon Affiliates plugin for WordPress (versions <= 7.8.1). The flaw is classified under CWE-497 (Exposure of Sensitive System Information to an Unauthorized Control Sphere), indicating that the application inadvertently reveals sensitive information to unauthorized users. While the Patchstack advisory mentions a 'Subscriber' privilege level in its metadata, the CVSS vector (AV:N/AC:L/PR:N/UI:N) suggests the data may be accessible over the network without authentication. Attackers can exploit this to view restricted system or user information, which could facilitate further exploitation of the site. The issue is resolved in version 7.8.2.
Affected products
- RelyWP Coupon Affiliates <= 7.8.1
Timeline
- 2026-05-29: other: Reported by researcher Stefano
- 2026-06-09: advisory: Patchstack advisory published
- 2026-06-15: disclosed: CVE published in NVD
- 2026-06-09: patched: Version 7.8.2 released to address the vulnerability