WordPress security by component
Coupon Affiliates
Plugin description
Coupon Affiliates is a WordPress component with 11 published CVE records in this archive. The latest tracked vulnerability was published Jun 15, 2026; the highest CVE/CNA score is 7.5.
Plugin slug:
woo-coupon-usageLatest vulnerability
CVE-2026-49068: Coupon Affiliates: A security weakness
Coupon Affiliates is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 7.8.1.
| Safe version |
|
||
|---|---|---|---|
| Jun 15, 2026 |
CVE-2026-49068
Coupon Affiliates: A security weakness
Coupon Affiliates is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 7.8.1.
|
7.8.2 |
CVE7.5
NVDPending
|
| Jun 15, 2026 |
CVE-2026-40770
Coupon Affiliates: Cross-site scripting
Coupon Affiliates is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 7.5.3.
|
7.6.0 |
CVE7.1
NVDPending
|
| Oct 27, 2025 |
CVE-2025-62884
Coupon Affiliates: A security weakness
Coupon Affiliates is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Sep 22, 2025 |
CVE-2025-59567
Coupon Affiliates: A security weakness
Coupon Affiliates is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.5
NVDPending
|
| Aug 20, 2025 |
CVE-2025-54025
Coupon Affiliates: A security weakness
Coupon Affiliates is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Jul 16, 2025 |
CVE-2025-54022
Coupon Affiliates: Cross-site request forgery
Coupon Affiliates is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Apr 18, 2025 |
CVE-2025-3598
Coupon Affiliates – Affiliate Plugin for WooCommerce: Cross-site scripting
Coupon Affiliates – Affiliate Plugin for WooCommerce is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVDPending
|
| Dec 13, 2024 |
CVE-2024-12421
The Coupon Affiliates – Affiliate Plugin for WooCommerce: Cross-site scripting
The Coupon Affiliates – Affiliate Plugin for WooCommerce is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Mar 19, 2024 |
CVE-2024-29125
Coupon Affiliates: Cross-site scripting
Coupon Affiliates is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVDPending
|
| Aug 14, 2023 |
CVE-2023-30475
Woo Coupon Usage: Cross-site scripting
Woo Coupon Usage is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Jun 26, 2023 |
CVE-2023-28992
Woo Coupon Usage: Cross-site scripting
Woo Coupon Usage is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|