Description
WordPress Plugin WooCommerce Smart Coupons is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently send themselves gift certificates of any value, which could be redeemed for the products sold. WordPress Plugin WooCommerce Smart Coupons version 4.6.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.6.5 or latest
References
Related Vulnerabilities
PHP Out-of-bounds Read Vulnerability (CVE-2019-9021)
OpenSSL Cryptographic Issues Vulnerability (CVE-2009-2409)
WordPress Plugin Simple Download Monitor Cross-Site Scripting (3.5.3)
ReviveAdserver Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2016-9456)
Moodle Improper Access Control Vulnerability (CVE-2015-2267)