CVE-2026-45438: Webtoffee Smart Coupons For Woocommerce

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Missing Authorization vulnerability in WebToffee Smart Coupons for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Smart Coupons for WooCommerce: from n/a before 2.3.0.

Affected products

  • Webtoffee Smart Coupons For Woocommerce: before 2.3.0 (fixed in 2.3.0)

Published 2026-05-25. Last modified 2026-07-24.