Unauthorized Gift Certificate Creation Vulnerability in WooCommerce Smart Coupons
CVE-2020-36841
What is CVE-2020-36841?
The WooCommerce Smart Coupons plugin for WordPress has a vulnerability that allows unauthorized users to exploit a missing capability check within the woocommerce_coupon_admin_init function. This flaw affects versions up to and including 4.6.0, enabling unauthenticated attackers to create gift certificates of arbitrary value. Once generated, these certificates can be redeemed for products in the affected storefront, posing a significant risk to the integrity of online transactions and financial losses for merchants.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WooCommerce Smart Coupons * < 4.6.5
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved