Description
WordPress Plugin WooCommerce Smart Coupons is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently send themselves gift certificates of any value, which could be redeemed for the products sold. WordPress Plugin WooCommerce Smart Coupons version 4.6.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.6.5 or latest
References
Related Vulnerabilities
Joomla Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-3225)
WordPress Plugin underConstruction Cross-Site Scripting (1.18)
MySQL CVE-2018-3084 Vulnerability (CVE-2018-3084)
WordPress Plugin Metronet Tag Manager Cross-Site Request Forgery (1.2.7)
WordPress Plugin Digital Climate Strike WP Malicious Redirects (1.0.0)