CVE-2025-62884
Description
Missing Authorization vulnerability in Elliot Sowersby / RelyWP Coupon Affiliates woo-coupon-usage allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Coupon Affiliates: from n/a through <= 7.2.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Coupon Affiliates WordPress plugin <= 7.2.0 has a missing authorization vulnerability allowing unauthenticated access to restricted functionality.
Vulnerability
Overview
The Coupon Affiliates plugin for WordPress (woo-coupon-usage) versions up to and including 7.2.0 suffers from a missing authorization vulnerability. This means that certain functionality intended for privileged users is not properly protected by access control lists (ACLs), allowing unprivileged users to access it [1].
Exploitation
An attacker, either unauthenticated or with low-level privileges, can exploit this flaw by sending crafted requests to the vulnerable endpoints. No special authentication or network position is required beyond being able to interact with the WordPress site [1]. The missing authorization checks make it straightforward to invoke administrative actions without proper permissions.
Impact
Successful exploitation allows the attacker to perform actions normally reserved for higher-privileged roles, such as managing coupon data or affecting affiliate settings. This could lead to unauthorized coupon creation, modification, or disclosure, potentially enabling fraudulent discounts or revenue leakage [1].
Mitigation
The vulnerability is addressed in version 7.2.1 of the plugin. Users are strongly advised to update immediately. For sites that cannot be updated, implementing a web application firewall or restricting access to the vulnerable plugin's endpoints may temporarily reduce risk, but updating is the only complete fix [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <=7.2.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.