Missing Authorization Vulnerability in WebToffee Smart Coupons for WooCommerce
CVE-2026-45438
7.5HIGH
What is CVE-2026-45438?
A vulnerability exists in the WebToffee Smart Coupons for WooCommerce plugin that pertains to missing authorization measures, allowing unauthorized access due to misconfigurations in access control security levels. This flaw can be exploited by attackers to gain inappropriate access, potentially manipulating sensitive functionalities within the plugin.
Affected Version(s)
Smart Coupons for WooCommerce < 2.3.0