Description
WordPress Plugin WooCommerce Smart Coupons is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently send themselves gift certificates of any value, which could be redeemed for the products sold. WordPress Plugin WooCommerce Smart Coupons version 4.6.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.6.5 or latest
References
Related Vulnerabilities
MySQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-4097)
MediaWiki Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2021-36129)
Internet Information Services Other Vulnerability (CVE-2001-0334)
MySQL CVE-2021-2298 Vulnerability (CVE-2021-2298)
Oracle Database Server CVE-2012-0527 Vulnerability (CVE-2012-0527)