CVE Database /
CVE-2026-39508
CVE · Medium
CVE-2026-39508 — Advanced Coupons for WooCommerce – BOGO Coupons, Store Credit & WooCommerce Coupon Plugin [advanced-coupons-for-woocommerce-free] < 4.7.2
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-39508
|
Advanced Coupons for WooCommerce – BOGO Coupons, Store Credit & WooCommerce Coupon Plugin [advanced-coupons-for-woocommerce-free] < 4.7.2 |
— |
Medium
6.5
|
< 4.7.2
|
4.7.2 |
2026-03-28 |
—
|
CVE-2026-39508
The Advanced Coupons for WooCommerce Coupons plugin contains a security flaw affecting WordPress versions up to 4.7.1.1, allowing malicious users with at least contributor privileges to embed unauthorized code into certain webpage elements. This embedded code executes automatically when accessed by other users, posing a risk of web script injection.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings