VYPR
Medium severity5.3NVD Advisory· Published Oct 27, 2025· Updated Apr 27, 2026

CVE-2025-62884

CVE-2025-62884

Description

Missing Authorization vulnerability in Elliot Sowersby / RelyWP Coupon Affiliates woo-coupon-usage allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Coupon Affiliates: from n/a through <= 7.2.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Coupon Affiliates WordPress plugin <= 7.2.0 has a missing authorization vulnerability allowing unauthenticated access to restricted functionality.

Vulnerability

Overview

The Coupon Affiliates plugin for WordPress (woo-coupon-usage) versions up to and including 7.2.0 suffers from a missing authorization vulnerability. This means that certain functionality intended for privileged users is not properly protected by access control lists (ACLs), allowing unprivileged users to access it [1].

Exploitation

An attacker, either unauthenticated or with low-level privileges, can exploit this flaw by sending crafted requests to the vulnerable endpoints. No special authentication or network position is required beyond being able to interact with the WordPress site [1]. The missing authorization checks make it straightforward to invoke administrative actions without proper permissions.

Impact

Successful exploitation allows the attacker to perform actions normally reserved for higher-privileged roles, such as managing coupon data or affecting affiliate settings. This could lead to unauthorized coupon creation, modification, or disclosure, potentially enabling fraudulent discounts or revenue leakage [1].

Mitigation

The vulnerability is addressed in version 7.2.1 of the plugin. Users are strongly advised to update immediately. For sites that cannot be updated, implementing a web application firewall or restricting access to the vulnerable plugin's endpoints may temporarily reduce risk, but updating is the only complete fix [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.