
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1128 is a Cross-Site Request Forgery (CSRF) vulnerability in the WP eCommerce WordPress plugin that allows unauthenticated attackers to trick a logged-in administrator into deleting store coupons. It affects all versions of the plugin through 3.15.1, with no known fix available at the time of disclosure. The vulnerability was publicly disclosed on February 13, 2026, and assigned a CVSS v3.1 base score of 4.3 (Medium) (WPScan, Red Hat CVE).
The root cause is a missing CSRF token validation (CWE-352) on the coupon deletion endpoint in the WP eCommerce plugin's admin interface. An attacker can craft a malicious URL or hidden HTML form targeting the wp-admin/edit.php endpoint with the action=delete parameter and specific coupon IDs, then socially engineer an authenticated administrator into visiting or loading that URL. No authentication is required on the attacker's side — only the victim must be logged in as an admin. A proof-of-concept URL is publicly documented: https://example.com/wp-admin/edit.php?post_type=wpsc-product&page=wpsc-edit-coupons&action=delete&coupon[0]=4&coupon[1]=5 (WPScan).
Successful exploitation allows an attacker to permanently delete discount coupons from a WP eCommerce store without the administrator's knowledge or consent, impacting the integrity of the store's promotional configuration. There is no confidentiality or availability impact — the attack is limited to unauthorized data modification (coupon deletion). While not directly enabling lateral movement or data exfiltration, repeated exploitation could disrupt e-commerce operations by removing valid promotional codes (WPScan).
A public proof-of-concept URL is documented in the WPScan advisory, making exploitation straightforward for any attacker who can deliver a crafted link to a logged-in administrator. The EPSS score is very low at 0.000080, indicating minimal observed exploitation activity, and there is no evidence of in-the-wild exploitation or inclusion in CISA's Known Exploited Vulnerabilities catalog. No threat actor attribution has been reported (WPScan, Red Hat CVE).
https://victim-site.com/wp-admin/edit.php?post_type=wpsc-product&page=wpsc-edit-coupons&action=delete&coupon[0]=4&coupon[1]=5, substituting real coupon IDs./wp-admin/edit.php?post_type=wpsc-product&page=wpsc-edit-coupons&action=delete&coupon[]=... from unexpected referrers or external IP addresses.Referer header pointing to an external or unexpected domain.As of the disclosure date (February 13, 2026), there is no known fix available for the WP eCommerce plugin through version 3.15.1 (WPScan). Site administrators should monitor the plugin's repository for a patched release and update immediately when one becomes available. In the interim, consider disabling the plugin if coupon functionality is not critical, restricting admin account access, and training administrators to avoid clicking unsolicited links while logged into the WordPress dashboard.
The vulnerability was discovered and reported by independent researcher Bob Matyas, who also submitted it to WPScan. No significant vendor statements, major media coverage, or notable community discussion beyond the WPScan advisory have been identified for this moderate-severity issue (WPScan).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."