Coupon Referral Program [coupon-referral-program] <= 1.7.2 (unfixed)
unknown
[en] Deserialization of Untrusted Data vulnerability in WP Swings Coupon Referral Program.This issue affects Coupon Referral Program: from n/a through 1.7.2.
- Affected:
- up to 1.7.2
- Fix:
- No patched version reported
- Disclosed:
- Feb 12, 2024
CVE-2024-25100 on NVD →
Coupon Referral Program <= 1.8.3 - Unauthenticated PHP Object Injection
critical
The Coupon Referral Program plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8.3 via deserialization of untrusted input. This makes it possible for unuathenitcated attackers. to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain...
- CVSS:
- 9.8
- Affected:
- up to 1.8.3
- Fixed in:
- 1.8.4
- Disclosed:
- Feb 5, 2024
CVE-2024-25100 on NVD →
Coupon Referral Program [coupon-referral-program] <= 1.7.2 (unfixed)
unknown
[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WP Swings Coupon Referral Program.This issue affects Coupon Referral Program: from n/a through 1.7.2.
- Affected:
- up to 1.7.2
- Fix:
- No patched version reported
- Disclosed:
- Jan 8, 2024
CVE-2023-52190 on NVD →
Coupon Referral Program <= 1.8.4 - Sensitive Information Disclosure
medium
The Coupon Referral Program plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.4. This makes it possible for unauthenticated attackers to extract sensitive user data.
- CVSS:
- 6.5
- Affected:
- up to 1.8.4
- Fixed in:
- 1.8.5
- Disclosed:
- Jan 3, 2024
CVE-2023-52190 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database