Coupon Affiliates
by WordPress
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-49068 | Hig | 0.49 | 7.5 | — | Jun 15, 2026 | Subscriber Sensitive Data Exposure in Coupon Affiliates <= 7.8.1 versions. | ||
| CVE-2026-40770 | Hig | 0.46 | 7.1 | — | Jun 15, 2026 | Unauthenticated Cross Site Scripting (XSS) in Coupon Affiliates <= 7.5.3 versions. | ||
| CVE-2025-3598 | Med | 0.40 | 6.1 | 0.01 | Apr 18, 2025 | The Coupon Affiliates – Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the commission_summary parameter in all versions up to, and including, .6.3.0 due to insufficient input sanitization and output escaping. This… | ||
| CVE-2023-30475 | 0.00 | — | 0.00 | Aug 14, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Elliot Sowersby, RelyWP WooCommerce Affiliate Plugin – Coupon Affiliates plugin <= 5.4.5 versions. |
- risk 0.49cvss 7.5epss —
Subscriber Sensitive Data Exposure in Coupon Affiliates <= 7.8.1 versions.
- risk 0.46cvss 7.1epss —
Unauthenticated Cross Site Scripting (XSS) in Coupon Affiliates <= 7.5.3 versions.
- risk 0.40cvss 6.1epss 0.01
The Coupon Affiliates – Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the commission_summary parameter in all versions up to, and including, .6.3.0 due to insufficient input sanitization and output escaping. This…
- CVE-2023-30475Aug 14, 2023risk 0.00cvss —epss 0.00
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Elliot Sowersby, RelyWP WooCommerce Affiliate Plugin – Coupon Affiliates plugin <= 5.4.5 versions.