← WordPress Vulnerabilities
WordPress security by component

Coupon Affiliates

Coupon Affiliates is a WordPress component with 11 published CVE records in this archive. The latest tracked vulnerability was published Jun 15, 2026; the highest CVE/CNA score is 7.5.

Plugin slug: woo-coupon-usage

CVE-2026-49068: Coupon Affiliates: A security weakness

Coupon Affiliates is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 7.8.1.

PublishedJun 15, 2026
Known safe version7.8.2
Safe version
Jun 15, 2026 CVE-2026-49068
Coupon Affiliates: A security weakness
Coupon Affiliates is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 7.8.1.
7.8.2
CVE7.5
NVDPending
Jun 15, 2026 CVE-2026-40770
Coupon Affiliates: Cross-site scripting
Coupon Affiliates is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 7.5.3.
7.6.0
CVE7.1
NVDPending
Oct 27, 2025 CVE-2025-62884
Coupon Affiliates: A security weakness
Coupon Affiliates is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Sep 22, 2025 CVE-2025-59567
Coupon Affiliates: A security weakness
Coupon Affiliates is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.5
NVDPending
Aug 20, 2025 CVE-2025-54025
Coupon Affiliates: A security weakness
Coupon Affiliates is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Jul 16, 2025 CVE-2025-54022
Coupon Affiliates: Cross-site request forgery
Coupon Affiliates is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE6.5
NVDPending
Apr 18, 2025 CVE-2025-3598
Coupon Affiliates – Affiliate Plugin for WooCommerce: Cross-site scripting
Coupon Affiliates – Affiliate Plugin for WooCommerce is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Dec 13, 2024 CVE-2024-12421
The Coupon Affiliates – Affiliate Plugin for WooCommerce: Cross-site scripting
The Coupon Affiliates – Affiliate Plugin for WooCommerce is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Mar 19, 2024 CVE-2024-29125
Coupon Affiliates: Cross-site scripting
Coupon Affiliates is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Aug 14, 2023 CVE-2023-30475
Woo Coupon Usage: Cross-site scripting
Woo Coupon Usage is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Jun 26, 2023 CVE-2023-28992
Woo Coupon Usage: Cross-site scripting
Woo Coupon Usage is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1