CVE-2024-13316: Akashmalik Scratch & Win

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the apmswn_create_discount() function in all versions up to, and including, 2.8.0. This makes it possible for unauthenticated attackers to create coupons.

Affected products

  • Akashmalik Scratch & Win: before 2.9.0 (fixed in 2.9.0)

Published 2025-02-18. Last modified 2026-06-17.