WooCommerce Smart Coupons <= 4.6.0 - Unauthenticated Coupon Creation
mediumThe WooCommerce Smart Coupons plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the woocommerce_coupon_admin_init function in versions up to, and including, 4.6.0. This makes it possible for unauthenticated attackers to send themselves gift certificates of any value, which...
- CVSS:
- 5.3
- Affected:
- up to 4.6.5
- Fixed in:
- 4.6.5
- Disclosed:
- Mar 4, 2020