CVE-2026-45438
Last modified
CVE-2026-45438 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Missing Authorization vulnerability in WebToffee Smart Coupons for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Smart Coupons for WooCommerce: from n/a before 2.3.0.. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
Missing Authorization vulnerability in WebToffee Smart Coupons for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Smart Coupons for WooCommerce: from n/a before 2.3.0.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-45438?
How severe is CVE-2026-45438?
How do I fix CVE-2026-45438?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-45432This vulnerability exists in GX Earth ONT models due to the …8.7
- CVE-2026-45433This vulnerability exists in GX Earth 2022 ONT models due to…8.7
- CVE-2026-45434Improper Authentication vulnerability in Apache OFBiz via Pa…9.8
- CVE-2026-45435Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2026-45436Subscriber Broken Access Control in WPBakery Page Builder <=…6.5
- CVE-2026-45437Unauthenticated Cross Site Scripting (XSS) in Product Filter…7.1
- CVE-2026-45439Unauthenticated SQL Injection in Realtyna Organic IDX plugin…9.3
- CVE-2026-4544A vulnerability was determined in Wavlink WL-WN578W2 221110.…4.8
- CVE-2026-45441Unauthenticated Other Vulnerability Type in WpEvently <= 5.3…7.5
- CVE-2026-45442Missing Authorization vulnerability in Brainstorm Force Pres…4.3
- CVE-2026-45443Missing Authorization vulnerability in ADD-ONS.ORG PDF for E…5
- CVE-2026-45444Unrestricted Upload of File with Dangerous Type vulnerabilit…10
Are you affected by CVE-2026-45438?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
