Missing Authorization Vulnerability in RelyWP Coupon Affiliates Plugin
CVE-2025-59567

4.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 September 2025

What is CVE-2025-59567?

A vulnerability has been identified in the RelyWP Coupon Affiliates plugin that allows attackers to exploit incorrectly configured access control security levels. This missing authorization risk affects users of Coupon Affiliates from version n/a up to version 6.8.0, potentially enabling unauthorized access and manipulation of sensitive data.

Affected Version(s)

Coupon Affiliates <= 6.8.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Legion Hunter (Patchstack Alliance)
.
CVE-2025-59567 : Missing Authorization Vulnerability in RelyWP Coupon Affiliates Plugin