Sceawere
Vulnerability Detail
CVE-2026-62081UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Flexible PDF Coupons IDOR Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.4
- Creation Date
- 3h ago
- Vendor
- wpdesk
- Product
- Flexible PDF Coupons
- Attack Type
- CWE-639 Authorization Bypass Through User-Controlled Key
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Contributor Insecure Direct Object References (IDOR) in Flexible PDF Coupons <= 1.14.11 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.4",
"pubDate": "2026-09-30T13:17:19.453Z",
"pubdate": "2026-09-30T13:17:19.453Z",
"executiveSummary": "The Flexible PDF Coupons plugin, in versions 1.14.11 and below, contains an Insecure Direct Object Reference (IDOR) vulnerability.\nThis vulnerability allows authenticated users with contributor-level privileges or higher to access, view, or potentially manipulate PDF coupon data belonging to other users or the administrative backend.\nThe flaw resides in the improper validation of object identifiers during server-side requests, failing to enforce strict authorization checks for the requested resources.\nSuccessful exploitation enables unauthorized data exposure, potentially revealing sensitive customer information or proprietary coupon data.\nThe attack is performed via direct object reference manipulation, requiring the attacker to possess an active session within the application. The vulnerability poses a significant risk to data confidentiality and integrity within the WordPress ecosystem.\nExploitation does not require elevated administrative privileges, making it accessible to any authenticated contributor account.",
"technicalDetails": "The vulnerability is an Insecure Direct Object Reference (IDOR) found within the Flexible PDF Coupons plugin (<= 1.14.11). An IDOR occurs when an application provides direct access to objects based on user-supplied input without performing adequate authorization checks.\nIn this instance, the plugin fails to verify that the requesting user has the appropriate ownership or permission level to access the specific PDF coupon resource requested through the application's parameters.\nThe root cause lies in the server-side logic responsible for handling requests for coupon resources. The application accepts identifiers (e.g., ID parameters) via GET or POST requests and retrieves the corresponding database object without validating if the current session's user ID matches the authorized owner of that resource.\nAttack flow: 1. The attacker, authenticated as a contributor, intercepts a legitimate request to retrieve a PDF coupon. 2. The attacker identifies the object identifier (typically a numeric ID) within the URL parameter or request body. 3. The attacker modifies the object identifier to target a different, unauthorized resource. 4. Because the application lacks a server-side permission verification mechanism, the backend processing logic processes the malicious request and returns the sensitive object data associated with the modified identifier.\nThis behavior exposes the application to unauthorized data retrieval, potentially allowing contributors to access sensitive coupon data that should be restricted to administrators or the original coupon creator. The vulnerability is effective because the application relies on client-side state or insecure references rather than implementing an robust access control list (ACL) or checking the ownership status of the requested object ID against the session's authenticated user ID.\nThe technical impact includes a complete breach of confidentiality regarding coupon data. Depending on the plugin's architecture, this could also lead to unauthorized modification if the same insecure pattern is applied to update or delete functions associated with the ID parameter."
}