CVE-2026-40770: WordPress Coupon Affiliates plugin <= 7.5.3 - Cross Site Scripting (XSS) vulnerability
Published Jun 15, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in Coupon Affiliates <= 7.5.3 versions.
Affected Software
1 affected component
WordPress Coupon Affiliates<=7.5.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/coupon-affiliatesto a version that resolves this vulnerability.Fixed in 7.6.0
Event History
Jun 15, 2026
CVE Published
via MITRE·08:18 PM
Data Sourced
via MITRE·08:18 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-40770?
CVE-2026-40770 has a high severity rating of 7.1.
2
What type of vulnerability is described in CVE-2026-40770?
CVE-2026-40770 describes an unauthenticated Cross Site Scripting (XSS) vulnerability.
3
Which versions of the WordPress Coupon Affiliates plugin are affected by CVE-2026-40770?
CVE-2026-40770 affects versions of the WordPress Coupon Affiliates plugin up to and including 7.5.3.
4
How can I mitigate the risk of CVE-2026-40770?
You can mitigate the risk of CVE-2026-40770 by updating the WordPress Coupon Affiliates plugin to a version above 7.5.3.
5
Is user authentication required to exploit CVE-2026-40770?
No, CVE-2026-40770 can be exploited without user authentication.