CVE-2026-45438: WordPress Smart Coupons for WooCommerce plugin < 2.3.0 - Broken Access Control vulnerability
Missing Authorization vulnerability in WebToffee Smart Coupons for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Smart Coupons for WooCommerce: from n/a before 2.3.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Smart Coupons for WooCommerce pluginto a version that resolves this vulnerability.Fixed in 2.3.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45438?
CVE-2026-45438 has a high severity rating of 7.5.
How do I fix CVE-2026-45438?
To fix CVE-2026-45438, update the WordPress Smart Coupons for WooCommerce plugin to version 2.3.0 or later.
What type of vulnerability is CVE-2026-45438?
CVE-2026-45438 is a Broken Access Control vulnerability.
Which versions of the plugin are affected by CVE-2026-45438?
CVE-2026-45438 affects WebToffee Smart Coupons for WooCommerce versions prior to 2.3.0.
What is the impact of CVE-2026-45438?
CVE-2026-45438 allows exploitation of incorrectly configured access control security levels.