Wordpress Alert: Coupon creation without authorization

A low-privilege account can create or modify coupons. An attacker may issue discounts that the store never approved.

What it looks like

A low-privilege account can create or modify coupons.

Why it matters

An attacker may issue discounts that the store never approved.

What to check

Check coupon-management permissions and recent coupon changes.

Documentation

This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See WooCommerce REST API overview, WordPress roles and capabilities.